Post #1398840
2026-03-23 18:19 UTC
@coderanger I've been thinking for a while now that it might be worth taking another shot at the web-of-trust. Long term, I think it's the only way forwards, but I agree unless it's dead simple to use it'll be impossible to hit critical mass. I think there will need to be some compromises on the theoretical security (TOFU vs key signing parties? verifying social media handles vs verifying government IDs?). If we could share a <128 character code on Mastodon (or Matrix or IRC) that served the same purpose as a GPG pub key, I think it'd be a lot easier to get people started.
I guess what I'm saying is: I recognize that getting a web of trust going is a Herculean task and that it failed once before, but in the absense of other good options I think it's worth considering whether we should take another stab at it having learned our lessons from the past.
Replies (1)
-
@malwareminigun@infosec.exchange 2026-03-23 20:35
@chansecodina @coderanger The problem is that web of trust would have done nothing against JiaTan. They were the upstream maintainer and had permission at a project level to mint the release they minted so they would have had the right keys.