Privacy software is flawed.
When developers make software, they cryptographically sign it to prove that they are the creator and it has no backdoor. Just like Nostr posts.
But unlike Nostr, we trust Microsoft’s Github and Cloudflare to give us the correct public key to begin with. This means all Github privacy software is potentially compromised. Even if you could convince all these open source devs to come on Nostr, their posts with the hashes would scroll off their feeds. Ideally, you want a website.
That’s where our PGP directory comes in. We’ve pointed blockchain domain names to websites that aren’t tied to a particular location or server (IPFS), to have a neutral third party source of information for you to compare to.
It’s easy to go to this website in Brave Browser, and verify your software with one command:
SimplifiedPrivacy.sol or SimplifiedPrivacy.x
And if you don’t know how to go to blockchain domain websites, here’s a tutorial:
https://simplifiedprivacy.com/ipfs-brave-browser/