Comment by fragsworth

11 years ago

That doesn't even remotely work, who has the private keys to authorize the certificates?

What authorization is required in this scenario? I'm talking about a novel idea here, one that doesn't fit into the existing CA model. There would be no CA in this scenario; verification would be decentralized, based on shared information, not on knowledge of a secret.

  • I'm not sure web-of-trust can be considered a novel idea in 2014.

    We can all look at the variety of web-of-trust methods to see how well that's taken off amongst internet users.