I agree, but I think it's pretty clear that web-of-trust has failed. There may be 6 or fewer degrees of separation between us, but the chance that there's a path of people that actually validate and sign keys isn't very high.
As an alternative keybase.io worked well. If you knew the person controlling the github account also controlled the mastodon/twitter where you talked to them, and the website/blog, etc, then you can be pretty sure it's them. (I saw mention of more open systems here too https://news.ycombinator.com/item?id=29132024).
> I'm all for using SSH keys for signing, but I still would like to have something like PGP's web of trust for those keys.
same here. I use my gpg key for ssh (stored on a yubikey). Seems like a better option to me.