These are third-party builds for Tor Browser on arm64

ZERO downloads of the asc file in a group that highly values privacy and security.

PGP-verifying is too hard to use and needs replacement

Reply to this note

Please Login to reply.

Discussion

It's not only that it's hard, everyone does it wrong.

Blindingly trusting a pgp public key is just security theatre. Most users don't really have a trust model for keys they accept as authentic.

Current best solutions are TOFU using WKD or keyservers. Using keyservers os worrying since anyone can submit a key, not to mention you're trusting the keyserver.

To be fair there were 21 downloads for the file asc (1.5%) which is virtually no-one