Topic: FireGPG incorrectly marks invalid signature as valid

On this page, FireGPG offers to verify the quoted inline-PGP message. I click on "Verify" and it says:

PGP Signed Message, This message has been signed with the valid key ID null

and turns the box green. On the previous page in the same thread (where the message was not quoted), FireGPG correctly (as I don't have the appropriate public key) says

PGP Signed Message, could not be verified.

Also, is there any way to be sure I'm actually receiving an authentic copy of FireGPG without compiling it myself? There are no detached signatures and the download page isn't even protected with SSL.

Thanks,
Bruce

Re: FireGPG incorrectly marks invalid signature as valid

Hi,

The first part is a bug. Added to the todo list wink.

Then for the authenticity of the copy :

There an sign inside the xpi who protect the addon again 'false' update (and let's it to be installed widhout ssl). But you're right, when you install firegpg for the first time, nothing let's you check if it's a good sign.

So I will add a sign on the download page asap (I plan to work a little bit on firegpg in next days).

Regards,

Re: FireGPG incorrectly marks invalid signature as valid

Hi

Sign add on the install page wink

Re: FireGPG incorrectly marks invalid signature as valid

Brilliant! Merci beaucoup smile

Re: FireGPG incorrectly marks invalid signature as valid

Fixed for the second bug wink