• @[email protected]
    link
    fedilink
    26 hours ago

    This is a joke right? I really really hope that they aren’t trusting randoms to know how to manage a gpg key properly.

    It’s hard enough to get people actually interested in it to do it correctly.

    And using gpg to constantly identify yourself would mean needing to keep multiple copies of your private key all over the place. I find it unlikely that regular people are issuing new keys and revocation certs properly. Not to mention having canonical key servers (maybe the government could manage that, but the individual is responsible for maintaining a way to get the canonical most up to date key)

    Using gpg backfires because if you lose access to the key or it’s compromised (say by putting it on your phone) you lose everything. They work for people who know what they are doing because you are supposed to issue keys for specific tasks and identities, but there is just no way that that is happening.