PGP Public Key

CrashBytes articles and public statements signed by Michael Eakins are PGP-signed with the key below. Verifying a signature proves the content was authored by the holder of the corresponding private key and has not been altered since signing.

Fingerprint

Verify this fingerprint out of band (printed material, an independent channel, the Wayback Machine snapshot of this page) before trusting the key. If the fingerprint here ever changes, do not import the new key without confirmation from a separate channel.

6329 5903 FC7B 24B0 FCF2  0F59 82FD B9B1 08E8 8F19
  • Identity: Michael Eakins (CrashBytes) <michael.eakins@blackholesoftware.com>
  • Algorithm: ed25519 (sign + cert) / cv25519 (encrypt subkey)
  • Created: 2026-05-09
  • Expires: 2028-05-08
  • Long key ID: 82FDB9B108E88F19

Get the key

Direct download: /pgp.asc — or import in one line:

curl -sSL https://crashbytes.com/pgp.asc | gpg --import

After import, confirm the fingerprint matches the one above:

gpg --fingerprint 82FDB9B108E88F19

Verifying a signed article

For a clearsigned message (Markdown / plaintext, signature appended in the file):

gpg --verify article.md.asc

For a detached signature (signature in a separate .asc file):

gpg --verify article.html.asc article.html

A successful verification shows Good signature from "Michael Eakins (CrashBytes) <michael.eakins@blackholesoftware.com>". GPG will warn that the key is not certified with a trusted signature — that is expected; trust comes from your out-of-band fingerprint check, not from the web of trust.

Public key (armored)

-----BEGIN PGP PUBLIC KEY BLOCK-----

mDMEaf9LZRYJKwYBBAHaRw8BAQdA0WuXtJdo8ncWCuP8AOEHg5ffH09184ZK0jof
iRTS5aS0Qk1pY2hhZWwgRWFraW5zIChDcmFzaEJ5dGVzKSA8bWljaGFlbC5lYWtp
bnNAYmxhY2tob2xlc29mdHdhcmUuY29tPoiZBBMWCgBBFiEEYylZA/x7JLD88g9Z
gv25sQjojxkFAmn/S2UCGwMFCQPCZwAFCwkIBwICIgIGFQoJCAsCBBYCAwECHgcC
F4AACgkQgv25sQjojxk3MwD/QgbBJvYYnzwUsB6jouKvcd5sogOVFN+KC9nq2haf
uGUA/3ee5U74yHVFZofZBg+IBA4wH6/NkJ1RTYH7exC2TA4IuDgEaf9LZRIKKwYB
BAGXVQEFAQEHQFVwnLgm5DOtcPxmwBX9V7C8HIuxVtMim+lMt8pki1hIAwEIB4h+
BBgWCgAmFiEEYylZA/x7JLD88g9Zgv25sQjojxkFAmn/S2UCGwwFCQPCZwAACgkQ
gv25sQjojxmPZwD+OkNro/bNS8l1xfEm19yikzv/AarxbKpMoStgdXbZVlUBAIRd
04SftKzhzN0ijiFIEBDPNjzZNhdmTCrI+pmoFr8L
=oq8Q
-----END PGP PUBLIC KEY BLOCK-----

Revocation

If this key is ever revoked, a notice will be posted on this page and a revocation certificate will be published at /pgp.asc in place of the live key. Treat any signed material whose timestamp falls after a published revocation as unverified.

Questions or issues with verification? Contact us.