38 ms·
For those already using PGP, that sounds great. For me, who is not using PGP, my set of trusted keys is currently empty. So it is unverified. Which, arguably,
by chaz72 12y ago
For those already using PGP, that sounds great. For me, who is not using PGP, my set of trusted keys is currently empty. So it is unverified.
Which, arguably, might be safer than being overly trusting of my "trusted CAs", which is verified by a flawed system.
I guess I'm still not thrilled wih my options overall, but thank you for your time explaining how to use PGP.
- dredmorbius 12y agoThe WoT is both PGP's strength and weakness. Lacking anything else, key security staff for various Linux distributions and key EFF members isn't a bad starting point for this. Assigning those "marginal" trust means that you'd have to have three of those signing a given key to trust it.
- chaz72 12y agoAh, now that is what I was looking for but didn't know how to ask. A few starting points I might trust would go a long way.