$ curl -S https://shrik3.com/gpg.asc | gpg --import
220F 6A50 7BEF 8C33 3B4A 4404 99DE B3B4 1583 4AEF
-----BEGIN PGP PUBLIC KEY BLOCK-----
mDMEZfl8VRYJKwYBBAHaRw8BAQdAnILhqWG/0UsMQHdA9Ju3OAj11Fh95p62yShr
vWuJYe60IVRpYW5oYW8gV2FuZyA8c2hyaWszQG1haWxib3gub3JnPoiTBBMWCgA7
FiEEIg9qUHvvjDM7SkQEmd6ztBWDSu8FAmX6FR8CGwMFCwkIBwICIgIGFQoJCAsC
BBYCAwECHgcCF4AACgkQmd6ztBWDSu+mwQD+MZZMGgppmFn4C3FGubOgBZzo1WPN
HI8FNRgCLiZbfLcA/RiogqqhyjqBDfqmhcMs3uSzweb1Iwag0ZMn2Lcb5tIJtBpz
aHJpazMgPHNocmlrM0ByaXNldXAubmV0PoiTBBMWCgA7FiEEIg9qUHvvjDM7SkQE
md6ztBWDSu8FAmX5fFUCGwMFCwkIBwICIgIGFQoJCAsCBBYCAwECHgcCF4AACgkQ
md6ztBWDSu8CXwD7BWsUmr9ROHYH2xnZEZWXDip+jE9VX3HrabaOb1bVLHAA+wYr
ZVzkMe8elZDuYESZ3zl/ijvfyOPUJl/igNMniMsOtCpUaWFuaGFvIFdhbmcgPHRp
YW5oYW8ud2FuZzJAdHUtZHJlc2Rlbi5kZT6IkAQTFgoAOBYhBCIPalB774wzO0pE
BJnes7QVg0rvBQJoUxW/AhsDBQsJCAcCBhUKCQgLAgQWAgMBAh4BAheAAAoJEJne
s7QVg0rvaNkBAJkBxRTGRU5vbpUNQ1paghMboexkCRQdZFXOps9kjSKIAP0QjUSr
9rzXuYr3sxVdlq8vSRH8s8PfNvCk/UlV+oPXAbg4BGX5fFUSCisGAQQBl1UBBQEB
B0BTmCCTi/6Pt/aVrU1dRNyhYRH+OZdb+XsUxBxDzCPIFwMBCAeIeAQYFgoAIBYh
BCIPalB774wzO0pEBJnes7QVg0rvBQJl+XxVAhsMAAoJEJnes7QVg0rvRr4A/ihD
AMe7dkJw+/ys3EI2Iq7mX3WiWDEjHpW0cR4SGJPkAP9s0SeDuQ3nqe1S1Asb/Ucq
xD5UNgyecOM2E3Kuk+r9AbgzBGX5fNMWCSsGAQQB2kcPAQEHQKoVoD8TBYpwwM9G
YXUkMT7AO2k6NlEVoLGAnU4jqitRiO8EGBYKACAWIQQiD2pQe++MMztKRASZ3rO0
FYNK7wUCZfl80wIbAgCBCRCZ3rO0FYNK73YgBBkWCgAdFiEEvNe3O8I0rLnc4alG
zMwImEH+mtAFAmX5fNMACgkQzMwImEH+mtAA2QD/bk9ciu8jUONNCbe07DdrE5NZ
NkXTwzCowXt+bvShNK0BAIiUm6PuN41/MHJWiEuWdXxxh2FBTUxgN4s69w/8LzkI
ZvoA/2IvUufJLcN4yhbZ57EOWa5RIb0+dBZ27x+j5G5+nIfFAP4ossUlMZTGoJZ9
N+fDo3Vlw6vVwwPTEt0ysf/pGaZ3CQ==
=2/sG
-----END PGP PUBLIC KEY BLOCK-----
retired key
DA29 39BC 46EF 7A36 FA08 B89F BBEE C439 23F0 E695
Don't use a public keyserver (ubuntu, openpgp, mit etc.)
if you find my key there it's likely outdated.
encrypt with age, if you prefer
age10uqv0kklww2r8szfahansgejz5t5330v0u4aj0mupll3net723xqa6dnec
$ echo "hello" | age -r <that-pubkey> -a encrypted.ascii
rules of thumb
- access via secure network connection (TLS) only!
- don’t trust a keyid unless it’s vouched (signed) by your web-of-trust.
- don’t trust a cert only because it’s found on a well-known keyserver. OpenPGP says: “whoever uploaded this cert has access to that email address (in the keyid)”.
- similarly, the cert you got from here says: whoever uploaded this cert has write access to this server.
- think for yourself to what extent you trust a thing