4 ms·
i don't think the web of trust as a "first principle" is necessarily a good thing. it made sense a while ago perhaps, but nowadays it's just overkill. there are
by mxxc 5y ago
i don't think the web of trust as a "first principle" is necessarily a good thing. it made sense a while ago perhaps, but nowadays it's just overkill. there are several use cases where either you want to keep a closed loop on everything (e.g. you intend keys to circulate only within your company), or very very different cases where there is value in keys that are valid only for the sake of a chat: it doesn't need to be anything illegal, but if two parties negotiate a message exchange and there is trust in the fact that the very first key exchange is secure, you only need the subsequent messages to match the first key pair. after that, the keys can safely be destroyed, not added to your respective keyrings and signed on the public internet.
- taeric 5y agoI'm not following. How does one build the trust in the first key exchange in a way that isn't building a web of trust? And your first example is just a small web of trust for the closed loop. That is, you are still leaning heavily on it as a first class thing. If the argument is that we don't need a global web of trust that everyone is always a party of, I can agree with that.
- mxxc 5y agoi think once most PGP implementations rely on public key servers + key signing a "global web of trust" is a first principle, while the "small web of trust" really isn't
- taeric 5y agoApologies on missing this. I agree that "global web of trust" is a bit tough. And I agree that reliance on far reaching trust is essentially that. The idea, though, seems to still hinge on the same concepts, whether writ large or small.