<div dir="ltr">As if anyone uses these for anything anyway.<div><br></div><div>I did have a thought the other day: It might be cool to buy one of the new .pub domains just to put one's key on though. I haven't done so, but e.g.</div><div><br></div><div>curl rory.pub | gpg --import</div><div><br></div><div><br></div></div><div class="gmail_extra"><br clear="all"><div><div class="gmail_signature"><div dir="ltr"><div>Rory Holland <me@rory.sh><br></div>Contact info & PGP key: <a href="http://rory.sh" target="_blank">http://rory.sh</a><br></div></div></div>
<br><div class="gmail_quote">On 21 November 2015 at 14:59, Roger Light <span dir="ltr"><<a href="mailto:roger@atchoo.org" target="_blank">roger@atchoo.org</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">On Sat, Nov 21, 2015 at 10:03 AM, <a href="mailto:david@gbenet.com">david@gbenet.com</a> <<a href="mailto:david@gbenet.com">david@gbenet.com</a>> wrote:<br>
<br>
> People had have my old key will be aware they share the same information.<br>
<br>
The point is that there's no guarantee it is in fact linked to you.<br>
They met you, presumably checked your credentials, then signed your<br>
key. This time, all there is is an email from someone alleging to use<br>
the same email address (which isn't the same as in the key), signed by<br>
the new key. Anybody could forge a mail with a fake gpg key saying the<br>
same, without some link between the old key and the new there is no<br>
reason to assume they are connected.<br>
<br>
I've attached a different gpg key with the exact same parameters as<br>
yours. By your reckoning, everyone should assume that it belongs to<br>
you as well, which is clearly not the case.<br>
<br>
If you don't care about the web of trust aspect, then sure ask people<br>
to sign your keys without verification, but you should bear in mind it<br>
then doesn't mean anything.<br>
<br>
Cheers,<br>
<br>
Roger<br>
<br>_______________________________________________<br>
Nottingham mailing list<br>
<a href="mailto:Nottingham@mailman.lug.org.uk">Nottingham@mailman.lug.org.uk</a><br>
<a href="https://mailman.lug.org.uk/mailman/listinfo/nottingham" rel="noreferrer" target="_blank">https://mailman.lug.org.uk/mailman/listinfo/nottingham</a><br></blockquote></div><br></div>