Sign files with Delta Chat profile

Just thought, since each Delta Chat profile has an OpenPGP key with the primary signing key, it would be cool if you can use it to sign files.

E.g. sign releases or webxdc’s with your profile, then use Delta Chat to verify signatures so if you know someone and have a long chat with them and multiple group chats, you can trust the file is signed by the DC contact.

Or maybe not sign the files directly, but create a signing subkey and export it (without exporting the primary key ofc), then use it with normal OpenPGP tooling.

5 Likes

This sounds great, especially combined with specific-use bots; a lot of FOSS comms and indeed systems run over e-mail.