Hacker News new | ask | show | jobs
by serichsen 3926 days ago
OK, so who manages the keys, and how?

I am aware of only two general principles to do this: centralized certificate authorities (possibly chained), and decentralized assurance, a. k. a. web of trust. Their advantages and drawbacks seem pretty clear by now.

So, which is it, and if a CA (which I'd assume), who has the keys and how is crytographic trust obtained?