Earlier quoted context omitted.
> > Put a Signal number on your security page to receive bug bounty reports, not a PGP key. Does anyone actually do this? Even Signal developers themselves don't! (see https://support.signal.org/hc/en-us/articles/360007320791-Ho... ). Instead there is a plain old email address where you are supposed to send your Signal number so that you can chat.
We manage bug bounties for a bunch of different startups, and I can count on zero fingers the number of times I've had to use PGP in the past year for that. In practice, people just send bugs with plain 'ol email.
So I think the result of removing PGP will be even more plain 'ol email than anything else.