|
|
|
|
|
by nvy
923 days ago
|
|
I think the common refrain against PGP is that it shouldn't be important, because it suffers from a myriad of technical and sociological shortcomings. The whole situation regarding key servers, key rotation, and the web of trust is a complete dumpster fire. |
|
Can you explain why?
People elsewhere in this thread are saying that PGP sucks because it tries to do too many things at once, but it seems to me that the one big advantage of a tool which does everything at once is that you only need to solve authenticity one time for everything you do.
For example, if I'm communicating with an open source dev, having their known-authentic PGP key allows me to simultaneously verify the authenticity of their software updates, verify the authenticity of the email they send me, and encrypt my emails to them. Is there anything outside of PGP that accomplishes this?