4 ms·
The so-called web of trust is meaningless security theatre. >They urgently need to make a "modern version" of GPG. Absolutely not.
by stackghost 9mo ago
The so-called web of trust is meaningless security theatre.
>They urgently need to make a "modern version" of GPG.
Absolutely not.
- Diti 9mo ago> The so-called web of trust is meaningless security theatre. Ignoring your comment’s lack of constructive criticism, I’m going to post this meaningful implementation that an excellent cryptographer, Soatok Dreamseeker, is working on: [1]. You may also search for his posts in this HN thread, his nickname is “some_furry”. [1]: https://github.com/fedi-e2ee/public-key-directory-specification https://github.com/fedi-e2ee/public-key-directory-specificat...
- zenethian 9mo agoKeyservers already “solved” this problem without needing federation because we only needed one keyserver anyway. Federating them isn’t going to do anything. Web of trust is a broken system that sounds super cool until you try to really use it. It has so many flaws that there’s really no way to revive it. Keybase tried to do something about it and also failed.
- some_furry 9mo agoTo be clear, this is not Web of Trust. It's using Key Transparency as a means to distribute public keys more securely than TOFU. If people want to build WoT on top of ny design, I won't stop them, but it's not a goal of mine.
- rolandog 9mo agoKeybase was doing great until it got acquired by Zoom and people felt uneasy about the implications, IIRC