Comment on Don't Trust, Verify (or: Validating Origin and Integrity without Public CAs)

BrianTheeBiscuiteer@lemmy.world ⁨4⁩ ⁨days⁩ ago

If there’s a concern that an adversary can rewrite hashes then why is there not a concern the public key could also be rewritten and the hashes signed with the fake key?

original
Sort:hotnewtop