3 ms·
Why is that a problem? If the hash is signed and the public key is trusted shouldn't that be secure?
by antnisp 11y ago
Why is that a problem? If the hash is signed and the public key is trusted shouldn't that be secure?
- cwyers 11y agoBecause someone can do a man-in-the-middle attack and intercept the right hash and replace it with another one. And how do you verify that the public key is trusted for the first time?
- antnisp 11y agoI was under the impression that you can have your key signed by a generally trusted CA.
- technion 11y agoGPG has no central CAs, but relies on a "web of trust" situation. In reality, there's no one central that everyone trusts, so unless the keys are signed by some individual you personally trust, you're down to being reliant on getting valid keys.