Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That is an extremely weird argument. They aren't separable concerns. If you have a trusted identity in place you could use a password-protected AES ZIP file for all the encryption matters.


There are too many threads, see: https://news.ycombinator.com/item?id=45919651. I don't see why we got here from PGP though.

> I think I'm missing something, how does asking for their public key improve security or verify their identity?

OK, so this was the question. My response should have been "it does not necessarily verify their identity". I mentioned some of the mechanisms for identity verification in the other thread.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: