FWIW, until I read somebody complaining about people uploading key
signatures, instead of sending them to the key owner, it never
occurred to me that it could possibly be a problem for anyone. My
immediate thought on reading it for the first time was that if it's a
bad thing, then the keyservers should prevent it. Even if it was
obviously a bad thing, people would still do it. So if it's completely
morally ambiguous, and possible, it's going to happen. No amount of
documentation or education will change that.

I mean, technically it should be easy for the keyservers to email the
owner of a key to ask if a signature should be accepted. Or to refuse
uploaded signatures unless they are themselves signed by the owner of
the key. If it really is a problem, then it can be fixed with code.

> Of course, ultimately Werner is the one who gets thumbs-up or 
> thumbs-down on this -- if it's to someday become the official FAQ,
> then he gets final signoff authority.  So if you disagree, feel
> free to pitch it to him, but you've heard my position on it.  :)

Doesn't matter what the FAQ says in this regard. It will continue to
happen unless the key servers actively prevent it.

