Re: Retrospective by 'gpg.fail' authors
oss-security follow-up to a gpg.fail authors' retrospective argues that GnuPG's unmaintained, forgotten code is a security liability and should be deleted.
On the oss-security mailing list, Soatok Dreamseeker responds to a retrospective published by the gpg.fail authors, asking why unmaintained code is retained and stating that forgotten, unmaintained code is a liability and effectively unmaintained by definition. The visible reply addresses Werner Koch and concerns GnuPG code maintenance. No specific CVE, flaw, or exploitation is described in this snippet.