@renard @LiveByReason @postmaster releasing unauthenticated plaintext, lots of things which should raise errors raise warnings which other tools interacting with it fail to use
You can convert an encrypted and authenticated data packet into an unauthenticated encrypted data packet and then modify the encrypted data without anyone noticing
Proper key separation was only implemented in the latest OpenPGP specification draft and GnuPG refuses to implement it