Posted Nov 2, 2006 15:20 UTC (Thu) by kleptog (subscriber, #1183)
[Link]
That puts web of trust at the issuer end, but does nothing for users. For example, I might trust a CAcert certificate to be from who it says, but that doesn't stop the person being a phisher.
The PGP documentation goes on about the difference being trusting the certificate belongs to a particular person, and whether the person is trustworthy in general. It's the latter I want to deal with...
The things I'm thinking of are someone getting a certificate setting up a fake banking site. I would like something to say "this site is from who it says it is, but it's not trusted by other people (and in particular, not by your buddy X)".