I was creating a new key for pass when I noticed a random expired GPG key assigned to a certain “Roderick van Domburg” in my list of keys. I don’t know any Rodericks, and this laptop has been whipped clean.

Should I be concerned? How could this even happen???

  • oscardejarjayes [comrade/them]
    link
    fedilink
    English
    3
    edit-2
    1 month ago

    Did you install anything from the AUR? roderickvd is the librespot guy, so if you installed that from the AUR it would load his keys

    • @tal@lemmy.today
      link
      fedilink
      English
      3
      edit-2
      1 month ago

      And the keyring was originally designed to hold all kinds of (public, not private) keys other then one’s own to build out the web of trust, so the intended mode of operation was to have other public keys in there. In practice, I think that most people just have their own keys, though.

      Never quite reached the dream of a distributed, verified network.