Hacker News new | ask | show | jobs
by aestetix 4330 days ago
I'm kind of sad the author didn't touch on key signing at all. The trust levels are basically meaningless. What does it mean to trust someone more than someone else? If doing a request to get someone's key exposes your social network, imagine what publicly signing someone's key does. Just some food for thought :)
1 comments

trust levels used during signing represent quality of identity check. in simple terms: if you checked ID of the person that is "sig3", if guy just claims the name on internet than it's "sig1"

on the other hand, "owner trust" is a local concept which is not exported and used solely for trust-path verification