https://docs.google.com/forms/d/19p-OY-Q5VKtVD2BVt8QVHMCcBO9...
"Hi. I'm Jesus!"
"Wow, Jesus? Nice to meet you, can I have your public key?"
I don't trust any of you :)
I don't care whether a Linux kernel release is signed by a guy who has government-issued ID that says "Linus Torvalds" on it. I care whether it is signed by the guy who started the whole thing more than 20 years ago.
There would be value in a modified web of trust where, when you receive an e-mail from hipaulshi, you can be certain that it's the same person you replied to on HN. Who cares what her (or his) real name is? In a sense, what you really want for most internet-centric communication is something like certificate pinning.
Of course things are different when you're talking about people who you know in person. But for those you don't have to organize key signing parties.
And even for people I know in the real world, I would be happy with a solution that just pins the very first public key it sees as long as nothing obviously suspicious is happening. This suffices for 99.9% of use cases. [0]
[0] No, this is not sufficient if you know that a government is out to get you. But if it helps to move us into an encryption-by-default setting, it is still a win for the overall ecosystem.
The alternative would be to confirm the fingerprint of the public key out of band, but lots of entities aren't already authenticated to each other (i.e. I can authenticate my best friend but not Amazon) and don't have a safe/practical way to check each other's public keys.
This is exactly the reasoning behind proposals such as TACK.
Edited to add: Keep in mind that external verification basically never happens, as much as cryptographers want it to happen. In the real world, you have a choice between no verification at all and a pinning-based verification which is weaker than the theoretical ideal, but makes MitM'ing significantly harder and much more likely to be detected for everybody at no user interface cost.
ADD: Fuck this statist cesspool.
Side note: maybe there could be a way to irreversibly hash one's fingerprint or DNA sample into an electronic signature
And this is part of why authentication and identity are very difficult things to do right, mostly because very few people have thought about what it is they're verifying.
If I publish a public key and say it belongs to me, 'Bob Smith', the only practical use that has is that you can verify that a future message signed by 'Bob Smith' was signed by someone with access to the same private key as the guy who originally published the public key. Any assumption about who 'Bob Smith' actually is, and who that corresponds to in the real world (what other identities do they assert), and also that 'Bob Smith' is a single entity, are simply assumptions.
It's impossible to pin a human down to a single, guaranteed verifiable, non impersonatable and non revocable identity. 'Documents issued by men with guns' isn't foolproof, but we use it as a trust anchor mostly because everyone else does, and we don't have much alternative.
1. A person has only one genetic code in their body.
2. A person's genetic code never changes.
etc. In the spirit of "falsehoods programmers believe about names" and "... about addresses".Obviously noone has the capability to do this, so they present you instead with "most likely" results. Not the level of proof I'd be looking for in a court of law.
Most of the time, this doesn't matter, but if we're talking about taking hashes for security, suddenly it does.
I'm thinking identical twins. Got anything for #4?
http://www.cryptnet.net/fdp/crypto/keysigning_party/en/keysi...