On Thu,  1 Sep 2016 08:34, miri...@riseup.net said:

> Ensuring that you keep talking to the same key is pretty easy. The
> hard thing is knowing what key is correct for someone who's defined
> only by an online presence. Where you have no WoT overlap. Comparing

You see signed message from someone and over time you build up trust.
Eventually you want to send a mail and the TOFU system will consider
that email/key valid due to the signatures gathered over time.


Salam-Shalom,

   Werner

-- 
Die Gedanken sind frei.  Ausnahmen regelt ein Bundesgesetz.
 /* Join us at OpenPGP.conf  <https://openpgp-conf.org> */

Attachment: pgpvZrGgH3yhH.pgp
Description: PGP signature

_______________________________________________
Gnupg-users mailing list
Gnupg-users@gnupg.org
http://lists.gnupg.org/mailman/listinfo/gnupg-users

Reply via email to