Ask HN: OTR/GPG/etc do not pin certificates, why?

https://news.ycombinator.com/item?id=8971422
by cyphunk • 11 years ago
2 0 11 years ago

These and other asymmetric cryptography schemes depend on trust through peers (WoT) or direct trust through out-of-band verification of key fingerprints. Yet the large majority of users don't bother with either. A horrific problem for activists but does not make use of these technologies entirely useless, if at least they would pin certificates in a meaningful way.

Why do these technologies not provide a level of trust based on "initial certificate" so that at least a MiTM attack happening later would provides an alert "This persons key has changed!". So what are the reasons for this not happening already?

Related Stories

Loading related stories...

Source preview

news.ycombinator.com