Hacker News new | ask | show | jobs
by aaomidi 913 days ago
There is a huge opportunity here for Apple to do a proper chain of trust.

“You want to talk to Adam, but you haven’t verified their keys yet. However your contacts Anna and Derek have confirmed Adam’s identity”

2 comments

This is such a privacy leak that I have a hard time thinking you're serious.

“You want to talk to Family Lawyer D. Ivorstein, but you haven’t verified their keys yet. However your contact Wife has confirmed D. Ivorstein’s identity”

Perhaps you could address that issue through explicit "family" or "friend" groups, where people can chose who they wish to verify for. That would limit the usefulness of the trust network but prevent the privacy issue you mention.
It would have to be an optional sharing. The UX would need a bit of work.

I would trust my technical friend with their chain of trust, but not my hair dresser.

I'm always confused by this. This merely validates that Anna at the time thought that was Adam's number, what else?

Does not guarantee it's Adam reading.

If you have a cryptographic primitive and a robust system to protect it (secure hardware, biometric auth), if you can confirm digital identity in real life you can be reasonably assured Adam is reading. Chain of integrity.
Just like blockchain, meat space applications of digital chains of trust require too much benevolence. At the end of all the state of the art crypto is Grandma pushing a button.
Speaks to the robustness of the legal system, and code simply a crude layer on top of it.
At its best it verifies that "Adam" is using a device that was verified by a trusted 3rd party as being added to the network by Adam himself. So, it is more about trusting devices than individual interactions.