The disadvantages of online KSP

David Shaw dshaw at jabberwocky.com
Sat Dec 25 21:33:42 CET 2004


On Sat, Dec 25, 2004 at 08:44:45PM +0100, Ben Branders wrote:

> As already discussed in another thread, there will be a keysigning
> party for Flanders (Belgium) and the Netherlands. This KSP will take
> place online (via IRC) and the participants won't meet eachother in
> real life.
> 
> Naturally, the biggest disadvantage is that you can't verify that
> the person really is who he says he is. You can check if the
> e-mailadres belongs to him, but there is no way of knowing if he is
> an impostor or not.
> 
> But then again, you can never know for sure that someone is an
> imposter or not. There are a lot of people who share exactly the
> same name. Even if you check their identity in real life, one of
> them can mislead you...

Signing someone's key is you making a statement that you have checked
that the key belongs to the person named in the user ID.  You really
can't do that in a strong way without meeting physically.

I would not sign someone's key under such circumstances.

David



More information about the Gnupg-users mailing list