GPG verification of NoScript XPI files

Ask for help about NoScript, no registration needed to post
ClaspMT

GPG verification of NoScript XPI files

Post by ClaspMT »

Hi. As someone who's trained in the humanities, between Tor and Debian there appears to be a lot of trust placed in the GPG system. Verifying Tor with gpg seems reasonable, but updating a gpg verified TorBrowser with an XPI file unverified at the same level seems somewhat counterintuitive in terms of security. Is there a gpg detached signature available for verifying NoScript releases? I apologize if this question's been asked and answered here before, but unfortunately I couldn't locate any relevant posts.
Mozilla/5.0 (Windows NT 6.1; rv:31.0) Gecko/20100101 Firefox/31.0