Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think you may have misread my comment, since I never claimed it was not possible to use PGP without web of trust. I claimed that it was a pain in the ass.


Its a pain in the ass because nobody has created a user friendly UI for that, but in itself it is a powerful technique to establish trust.


PGP’s UI isn’t user friendly to begin with, in fact, it’s notoriously bad. But that’s not the point. You try to get PGP to verify a signature without importing the key into a keychain fist.

The purported benefits of web of trust are completely irrelevant, the problem is that PGP handcuffs you to the web of trust and web of trust is often unwanted. You have to reduce and simplify your trust to something that PGP understands. There is no reason on this earth that signature verification should require importing shit into a database.

The whole philosophy of “do one thing well” would be nice here. PGP never lets you do one thing, it makes you buy the whole banana.


Pgp does not handcuff you to the web of trust. Actually most people who use pgp do not use the web of trust but instead compare fingerprints or do trust on first use.

If you do not understand this your argument is moot.

It is not because you learned in class that pgp works with the web of trust that this is what actually happens in practice




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: