Re: [portable] OpenPGP signatures on release checksums (#12)

2014-07-20 Thread Stefan Fritsch
On Monday 14 July 2014 12:45:35, Bob Beck wrote: > $ wc -l *.c > 29 crypto_api.c > 143 mod_ed25519.c > 327 mod_ge25519.c > 806 signify.c > 1305 total > > Signify is 1305 *lines* of C code. and it's included in our > development platform. It is not that difficult to install

Re: [portable] OpenPGP signatures on release checksums (#12)

2014-07-14 Thread Bob Beck
It's also here :) 8<-- untrusted comment: LibreSSL Portable public key RWQg/nutTVqCUVUw8OhyHt9n51IC8mdQRd1b93dOyVrwtIXmMI+dtGFe On Mon, Jul 14, 2014 at 8:52 PM, Bob Beck wrote: > > Once we are back in North America where we can do it (the master signature > box is airgapped) in case you're

Re: [portable] OpenPGP signatures on release checksums (#12)

2014-07-14 Thread Bob Beck
To answer a number of questions about this all at once. No. we don't sign releases with GnuPG or OpenPGP. GnuPG alone is a compressed tarball of 4.2 MB of code I have occasionally had to glance at. I do not have enough energy in my life to clean up two poorly written crypto code bases. The world