3 ms·
I don't understand how using HTTPS for the API has any bearing whatsoever on the WoT built via PGP. You can still verify the keys with your client's cached cop
by bqe 13y ago
I don't understand how using HTTPS for the API has any bearing whatsoever on the WoT built via PGP.
You can still verify the keys with your client's cached copies, or using another PGP client.
- FiloSottile 13y agoExactly, and moreover. If there is no trust in the server, everything can even go over unencrypted HTTP. CAs have no business here.