top | item 9012550

(no title)

fubarred | 11 years ago

PGP is fine. People aren't using it correctly.

The point of Web of Trust is to only trust keys that other people you know have also signed. Everything else is garbage until proven otherwise.

Key servers are untrustworthy because anyone can upload random shit to them.

Trying to shift WoT to a third party is trying to get something for free that doesn't emphasize solving the problem: getting everyone you know signing keys of only other people they know.

https://www.kernel.org/signature.html#kernel-org-web-of-trus...

discuss

order

joepie91_|11 years ago

PGP is extremely hard to use, so no, it's not "fine". Usability is just as important as (if not more important than) cryptographical correctness!