|
|
|
|
|
by bdamm
4328 days ago
|
|
PGP is only trustworthy if both parties treat key management with the utmost severity, and if everyone in the conversation maintains the integrity of a given thread (in the email case). There are a precious few individuals for whom I have that level of trust in their management of their private key. I could not even trust my wife to manage a hardware key that I gave her, it would fall apart immediately; "I cannot use this key on my chrome book? I cannot use this key on my Galaxy? I cannot use this key on my iPad? Give me a soft key that I can use, or a cloud service..." Therefore, PGP is not mainstream. There is a large population of people doing it incorrectly, and they must because they have no other real choice. |
|
* PGP is only trustworthy if both parties treat key management with the utmost severity.
* Transparent key management systems that rely entirely on heuristics and click-through warnings are trustworthy.