Hacker News new | ask | show | jobs
by Velox 4490 days ago
Signing the key is the important part. Proving that the key was in fact created by the people it was supposed to be. (I think they key does have to be kept secure, which could be done by using a one time pad. Theoretically unbreakable.)
1 comments

Right, that part I get. But isn't the security of the resultant key now left entirely to Verisign?
I think that's why the key is only valid for 3 months.