Comment by thayne

2 days ago

If the scan also included a picture, that was signed with your private key, then it would be harder to spoof.

Not really, the attacker would just need a picture of you which he could then sign (since we're assuming here that he gained access to your key IIUC). That's a pretty low bar compared to the first step of gaining the key.