|
|
Log in / Subscribe / Register

PGP trust

PGP trust

Posted Jun 30, 2010 18:18 UTC (Wed) by tialaramex (subscriber, #21167)
In reply to: Two GCC stories by ptman
Parent article: Two GCC stories

PGP even makes this explicit, and documents the difference, explaining that you may want to sign the identity of your naive best friend Bill on his key, knowing that it's really his key, but not trust him to authenticate other people's keys. Bill's naivety doesn't make his key any less authentic, but it makes his claims about the identities associated with other keys untrustworthy because he is easily fooled.

Further, PGP lets you "score" this property and set rules like "if the scores of the people who've signed this identity add up to 14 or more then assume it is real". This is in practice too advanced for most users, but it's there if you have a real use case for the web of trust.


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds