On 26/07/13 17:31, Jan wrote:
> I'm thinking of someone how uses windows and wants to install gnupg for the
> first time. How can he/she rely on OpenPGP?

By running a Linux Live CD to do the verification. How does he know the CD is
genuine? The thing is, somewhere the trust has to start. It's a bootstrapping

Also, how do you trust the OpenPGP signature is made by the correct key, etcetera.



