Hacker News new | ask | show | jobs
by geekbeast 4289 days ago
Agreed.

Without a trust the only thing that comes close is an in person P2P pairing ceremony.

Key management might work in an enterprise setting with a central authority, but making sure your friend's public key isn't swapped with the government's is pretty hard if you don't trust the cloud provider, telecom, or intermediate infrastructure.