|
|
|
|
|
by kpcyrd
444 days ago
|
|
There is nothing that can be done beyond what they are doing? You can receive their public keys out-of-band through an https-authenticated connection. Which means their approach to "the initial trust problem" is _not_ "trust on first use". |
|