This page (http://www.drand.ru/signatures/) is the place to get the current PGP keys used to check signatures on software you can obtain
from www.drand.ru and secure the confidence and identification. Any revocation certificates will also be posted here, should the key be compromised.
Note that a valid signature does not guarantee that this site itself hasn't been compromised, unless you're using a copy of the key that you had for long enough for a possible intrusion to be detected.
Also, you should probably not trust a new key you might find here unless there's also a valid revocation certificate for the old one.
Keep in mind that, if this site ever gets compromised, an intruder would be able to replace the public key posted here, not just a software package they might want to backdoor. This is the reason for the above measures.
Also note that one had better make separate inquiry on E-mail in order to get key for compare with.
|
|