> Having said all that you are CORRECT even a verisign
> ID is not infallable but 
> I still firmly believe verisign is 1000 times better
> than a home grown 
> version. :-) 

I'm sure John is currently foaming at the mouth.

To sign up for verisign you send them a document
(passport etc) and they confirm that you are that
person.  As you've said, this is rather easily broken
(send a stolen passport, you are that other person).

The web of trust works by me saying I am who I am. 
Then sparkes saying, yup he is who he is.  If you want
to check I am who I say I am you follow the path...
"oh, if sparkes says who he is he /must/ be who he

Of course, this method too is pretty breakable, unless
sparkes has seen my passport etc does he actually know
I am who I say I am?

But at least the second method is free :)

