It's true that PGP is a very good code signing system, but saying that sounds like an endorsement of PGP as a privacy system. (And there are plenty of other good code signing systems, from TUF to Authenticode to signify.)
It's true that PGP is a very good code signing system, but saying that sounds like an endorsement of PGP as a privacy system. (And there are plenty of other good code signing systems, from TUF to Authenticode to signify.)
This vaguely sounds similar to how RSA decryption/encryption and signing/verification are the same sets of operations, at the primitive level, making it easy to turn a tool that does one in to a tool that also does the other. But the actual high-level signing and encryption systems (e.g. RSA-PSS and RSA-OAEP) are not the same operations at all, and being good at one is no guarantee of being good at another.
Same basic concept. Take a blob (compiled code or cyphertext) and a private key and sign it, so can be verified with the public key later.
https://en.wikipedia.org/wiki/Authenticated_encryption
This kind of PGP signing is also critical to the security of Linux software repos. Debian repos sign the contents of the manifest (which includes hashes of packages), and Apt repos sign individual files.