It would be useful for the ZeroNet website to list @HelloZeroNet's OpenPGP pubkey. This would help users triangulate to make sure they have the correct key, in case the user's connection to GitHub is compromised.
Including both the full key (as a .asc file) and the 160-bit fingerprint would be ideal, since the fingerprint by itself is subject to censorship by keyservers (and also the fingerprint is based on SHA1, which is insecure), but the fingerprint is useful to triangulate via keyservers if the keyservers are available.
It would be useful for the ZeroNet website to list @HelloZeroNet's OpenPGP pubkey. This would help users triangulate to make sure they have the correct key, in case the user's connection to GitHub is compromised.
Including both the full key (as a
.asc
file) and the 160-bit fingerprint would be ideal, since the fingerprint by itself is subject to censorship by keyservers (and also the fingerprint is based on SHA1, which is insecure), but the fingerprint is useful to triangulate via keyservers if the keyservers are available.