Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> If you decide to add the cert manually, you can inspect the key and see who has signed it, and decide your level of trust.

No one has signed it, because the mythical web of trust does not exist. What now?



Contact the developer (say, over IRC, Slack, email, GitHub, etc), and ask them to sign a sentence you provide with it. Then you can sign their key.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: