TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Hello, OpenPGP CA

77 pointsby nwalfieldabout 4 years ago

4 comments

lapinotabout 4 years ago
This makes so much sense since every identity exists in the context of some authority, some common referential. You&#x27;re never completely alone as the pgp-classic web of trust implies, instead you&#x27;re trusting some centrally managed keys like your distros packet signers wich you always blindly accept.. The problem is we rarely sign keys as introducers (and rightfully so) since being a CA is a big responsability. CAs are not real persons. We should probably trust a handful of public CAs with well-defined scopes (some private network, some org), a couple smaller private groups and the exceptional direct trust for the closest friends we interact with daily..<p>Looking forward to using this.. Although in my case the source of thruth wouldn&#x27;t be openpgp keys but perhaps wireguard keys to our vpn or maybe omemo or ssh keys.
评论 #27138224 未加载
upofadownabout 4 years ago
I really like the term &quot;Scoped Trust Signatures&quot; and will steal it. An informative way to describe that mostly unknown and underappreciated OpenPGP feature.
nine_kabout 4 years ago
This is huge.<p>OpenPGP can becope usable in a scope of a realistically large organization, and most of the hassle can be put on the shoulders of dedicated IT people, instead of every user.
mawiseabout 4 years ago
What&#x27;s the difference between this and an in-house centrally managed CA?
评论 #27138283 未加载
评论 #27137759 未加载