← Back to context

Comment by fragsworth

11 years ago

That doesn't even remotely work, who has the private keys to authorize the certificates?

What authorization is required in this scenario? I'm talking about a novel idea here, one that doesn't fit into the existing CA model. There would be no CA in this scenario; verification would be decentralized, based on shared information, not on knowledge of a secret.

  • I'm not sure web-of-trust can be considered a novel idea in 2014.

    We can all look at the variety of web-of-trust methods to see how well that's taken off amongst internet users.