3 ms·
I agree, but I think it's pretty clear that web-of-trust has failed. There may be 6 or fewer degrees of separation between us, but the chance that there's a pat
by kenmacd 5y ago
I agree, but I think it's pretty clear that web-of-trust has failed. There may be 6 or fewer degrees of separation between us, but the chance that there's a path of people that actually validate and sign keys isn't very high.
As an alternative keybase.io worked well. If you knew the person controlling the github account also controlled the mastodon/twitter where you talked to them, and the website/blog, etc, then you can be pretty sure it's them. (I saw mention of more open systems here too https://news.ycombinator.com/item?id=29132024 https://news.ycombinator.com/item?id=29132024).
> I'm all for using SSH keys for signing, but I still would like to have something like PGP's web of trust for those keys.
same here. I use my gpg key for ssh (stored on a yubikey). Seems like a better option to me.
- notatoad 5y agoi think the main assumption that keybase makes is an important one: you don't need to link a key to a person, you need to link it to an identity. and a github page or a twitter account is an identity. the IRL identity of the person controlling that web identity can be considered out of scope. if you do need to link a key to an actual non-digital person, then you've got a whole different set of problems.
- GekkePrutser 5y agoThe problem of gpg/PGP servers is that they never counted on the phenomenon of 'spammers'. I have not put my key in a public directory for at least 15 years now.