|
|
|
|
|
by dispose13432
3454 days ago
|
|
Web of Trust seems to be an inherently broken paradigm. Think about this. Let's say I trust my friends (so when my friends sign John Doe is John Doe, it's really him). It's a big deal (not every friend is so security conscious, maybe he met this guy on facebook and looks so real), but would I trust someone because of a friends-friend's recommendation? I know which friends are naive. But which friend's-friend's-friend is naive? And those are the only web-of-trust connection I have with him? Can I trust him? Can I not? How do I tell? |
|
It's of course up to you to decide who you can trust to certify other keys.
edit: It's worth mentioning, "owner trust" is strictly a local attribute -- just because you fully trust John, and I fully trust you, my trust for John's certification of 3rd party keys remains unknown.