Don't trust a webpage — check it against something the page can't control. Everything I ship and sign can be verified with the keys below, and the same fingerprints go out in a signed note from my Nostr key. If this page and that note ever disagree, something is wrong — don't trust either.
My primary cryptographic identity. Notes signed by this key are me:
npub1hv288dxp0a5emsptlsnu5cw496mgh4l8suzfndkvuruxzfr8909sdqkqdn This site and that key point at each other, and you can check both directions without trusting either one on its own:
medampudi.com/.well-known/nostr.json.
That is the NIP-05 record behind my verified address [email protected].
I sign software releases and important documents with this
minisign key.
The public key is also served as a file: /rajesh-medampudi.pub
untrusted comment: minisign public key 0CDC6DA063220C50
RWRQDCJjoG3cDNBpGGjFdULwyP1xWiSk6MiPBFrWysMlDfVuGvaG13Xz For encrypted email and PGP-native verification. Fingerprint:
0EAE AFC5 F896 560D 56E6 8E77 3E5A 9FE1 12B0 22E6
Modern mail clients discover this key automatically from my address
([email protected]) via WKD served from this domain. Also available:
/rajesh-medampudi.asc ·
keys.openpgp.org
brew install minisign # macOS
apt install minisign # Debian/Ubuntu curl -O https://rajesh.medampudi.com/rajesh-medampudi.pub .minisig signature next to it):
minisign -Vm the-file.tar.gz -p rajesh-medampudi.pub
If it prints "Signature and comment signature verified", the file is genuinely from me, untampered. If it errors, don't use the file — and tell me.
A webpage alone is a weak proof — whoever controls the server controls the page. So the same fingerprints are published on channels I'd have to be compromised on separately. If they ever disagree, trust none of them and ask me in person.
0CDC6DA063220C50. It is signed, so it can't be forged or
edited after the fact.
Verification shouldn't require a cryptography degree. That's the point of this page — and of everything I do.