> Except maybe not: if you happen to do this with GnuPG 2.0.18 -- one version off from the very latest GnuPG -- the client won't actually bother to check the fingerprint of the received key.
Even in it's long form, it's relatively easy to generate different keys that have the same fingerprint.