Flatsonar

Keysign

by Tobias Mueller

OpenPGP Keysigning helper

Dangerous permissions Flathub reviewed GPL-3.0-or-later v1.2.0
Screenshot 1 of Keysign Screenshot 2 of Keysign

About

GNOME Keysign allows signing OpenPGP keys comfortably and securely via the local network or Bluetooth.

It can scan another key's barcode and transfer the key securely, allowing for casual two-party key signing sessions. It follows best practises by sending the encrypted signatures to the UIDs of a key using the Email client the user configured to use.

Permissions

5 permissions weaken the sandbox. Flatsonar asks before installing.

  • all devices (/dev): webcams, disks, raw hardware
    --device=all
  • access to a sensitive location (~/.gnupg): credentials or autostart
    --filesystem=~/.gnupg:ro
  • X11 display: X11 lets apps read input and windows of other apps
    --socket=x11
  • talks to system service org.freedesktop.Avahi
    --system-talk-name=org.freedesktop.Avahi
  • talks to system service org.bluez
    --system-talk-name=org.bluez
  • inter-process communication (needed for X11)
    --share=ipc
  • network
    --share=network
  • access to xdg-run/gnupg
    --filesystem=xdg-run/gnupg:ro
  • access to ~/.claws-mail/tmp
    --filesystem=~/.claws-mail/tmp:ro
  • Bluetooth
    --allow=bluetooth

Who publishes this

On Flathub: the manifest was reviewed and built on Flathub's infrastructure, but the developer has not verified ownership of the app id.

  • fetches from prdownloads.sourceforge.net over unencrypted http: anyone on the path can swap the bytes
    source:insecure-url
  • https://github.com/gnome-keysign/gnome-keysign also publishes this app id
    publisher:collision
  • on Flathub: manifest reviewed and built by Flathub; the developer has not verified the app id
    publisher:flathub

Maintenance

Recent activity on the upstream repository, or built and reviewed by Flathub.

No staleness signals: recent activity, or built and reviewed by Flathub.