|
|
|
|
|
by cyphunk
4452 days ago
|
|
If you only meant verifying the email as apart of a keysigning party, agreed. Meaning you are looking at their passport and sending an email at the same time. This is better than nothing but wont protect against many directed attacks. For instance, a journalists has to be more careful. Also, in the end if you are sitting in front of each other might as well just verify key fingerprints. Better privacy and security than a simple email verification. If the author meant actually sending someone a email to see that it is indeed owned by them remotely: NO WAY. Does not work: me: "hey, just sending you an email to confirm its really you before sending the secret plans?" them: "yeah, its me. send the plans." That is exactly what WoT tries to solve but can't due to misuse. |
|
What kind of attacks is this practice vulnerable to?