Hacker News new | past | comments | ask | show | jobs | submit login

> it was implicitly assumed that people attending a key parting were savvy enough to understand how to sign

It's not only about being savvy though. You trust the person to not misuse his/her key unknowingly or knowingly. If you only use marginal trust on a key signing party then it can be mitigated somewhat though. What's the usual trust level used on such a party?

Edit:

Then the Putty master key is misused according to you: https://pgp.mit.edu/pks/lookup?op=vindex&search=0x4F5E6DF56A...




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: