PGP Signed Comments
golem.ph.utexas.edu
golem.ph.utexas.edu
There is at least one major flaw, which is that GPG keys can and often do expire, and this presumes “live” verification of comments and a single global GPG key associated with a domain. So once you replace the master GPG key for your domain, your old comments will flag as invalid/unverified.
One solution would be to have the domain able to list an arbitrary collection of keys (including old ones) rather than a single. Another would be to have one or more trusted sources of archival keys, which could be delegated from your domain with a different link rel. The verifier could make a time bounded request for the domain key from a compliant key server (this would have to be added, right now I don’t think the idea of a domain pgp key exists).
Another solution is simply for the comment publisher to store the fact that the comment was verified and shown it “verified” henceforth. Live verification would disappear as an option once the key expires. This is probably “good enough”.
You can condense the problem to a subset of keys though with a verification chain. When posted, a sequence number + key + msghash + verification result + last verification result is posted publicly. That makes a block. I supposed we could call that a blockcha.... dangit. I almost said the forbidden word.
e.g. GitHub shows whether commits have been signed by GPG.
An expired key doesn't necessarily need its secret replaced. The key can just have its expiry date extended.
Keybase even almost proved that you could automate a lot more of Web of Trust and make the UX overall much easier. (The LINK tag based approach to attestation in the article here is almost directly a predecessor to that.)
Identity without any attestation is hard to impossible to work with. Web of Trust wasn't the "best" solution to that, but PGP identity was built on/for Web of Trust. Web of Trust was necessary to PGP and was arguably a big part of why PGP failed to be people's preferred identity tech, because Web of Trust was too hard to get right and not enough people trusted Web of Trust.