Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Perhaps I don't understand the whole keyserver concept... But how is a keyserver not a centralised "IdP" like construct?



PGP keyservers talk to each other, if you send your key to GnuPG keyserver it'll end up on MIT's keyserver pretty soon.


Thanks. The WoT depends on not trusting the keyservers, but trusting that humans on the other end know whom to trust and get them to countersign each other's keys.

SSL CAs:GnuPG (GPG/PGP) -> Subversion:Git




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: