It can’t help to guarantee the truth, but it can be used to verify that information comes from a certain source.
So, for example, if Russia created a deep fake video of Zelensky declaring that Ukraine is giving up the war and that troops should stop fighting back, then that kind of misinformation could be disproven, if Zelensky normally uses GPG-signed communication.
Tanoh@lemmy.world 11 months ago
A bit of a nitpick, but important to keep in mind. The GPG signatures shows that someone that has access to the private key sent that message. If I somehow gets a hold of a copy of your key, I can send messages that seems to originate from you.
TheInsane42@lemmy.world 11 months ago
To nit-pick a tad more, when they have access to my key and have my passphrase so they can sign with it…
That’s why you set the passphrase on keys, gpg, ssh,… Never use a encryption without a key. That way you need posession (key) and knowledge (passphrase) to identify yourself. When you use ssh, use the ssh agent, when you have automated login which would be better to use without keyphrase, use a different pair (specify wuth -i option) and limit access with that to a fixed ip.
And always protect your key. No cloud backup…