Security and Usability Issues of Clear Signed Checksum Files

Feel free to add thoughts / comments:

I have created a whole case with an attack scenario, so that it can be considered as such. This also makes it more comprehensible. Maybe I need to open a ticket in pagure or so, not yet sure, as I don’t know off the cuff which team is responsible. But we’ll find out :classic_smiley: