But the issue that you cannot *know* whether or not your F17 system is compromised by checking it with F17 itself. That's the trust chain problem. To be sure you could trust the alleged F17 key, you would have had to have already downloaded a key asserting to be F16-signed. But to verify that, you would have to have downloaded a key asserting to be F15-signed, and you would have to have an F14-signed key for that, so on. Even if that chain-of-trust would work in theory, all the way back to the bootstrapping of the project, reality is that those older signed-key-packages don't exist (and never will).