Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

>I imagine it would be something handled pretty automatically for everyone.

Then your imagination fails you.

If it is automatic/easy, then you have the 'easy key' problem, such as the key is easy to steal or copy. For example is it based on your apple account? Then what occurs with an account is stolen? Is it based on a device, what happens when the device is stolen?

Who's doing the PKI? Is it going to be like https, but for individuals (this has never really worked at this scale and with revocation). Like most social media is posting content taken by randos on the internet.



When your account is stolen someone can create "official" documents in your name and impersonate you. There could be a system for invalidating your key after a certain date to help out with those situations.

For prominent people who actually have to worry about being impersonated they could provide their own keys.

The infrastructure could be managed by multiple groups or a singular one like the government. The point isn't to be a perfect system, it's to generate enough trust that what you're looking at is genuine and not a total fraud.

In a world where AI bots are generating fake information about everyone in the world, that kind of system could certainly be built and be useful.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: