Hacker News new | ask | show | jobs
by dredmorbius 4699 days ago
Please read a fundamental PKI text or FAQ. That isn't a viable threat model.

On the other hand, anyone at any time can create a key with any given name on it. Under PGP, trust is generally imbued through keysigning and trust metrics.

Keys are also cheap: two (or more) parties could create keys (or subkeys) they used exclusively for communications between themselves, if they so chose.