logoalt Hacker News

literalAardvarktoday at 3:15 AM4 repliesview on HN

Nothing really stopping an agent from getting a key


Replies

crotetoday at 3:18 AM

The agent can't exactly show up to an in-person key signing party, can it?

And how many people are both dedicated enough to go to key signing parties and stupid enough to let an agent act without supervision in the name of their real-world identity?

show 2 replies
thwartedtoday at 3:49 AM

Having a key isn't a distinguishing aspect, it's the position in the "web of trust" network that is important.

thewebguydtoday at 4:03 AM

That's what key signing parties are for. In person verification.

transmit101today at 9:04 AM

> Nothing really stopping an agent from getting a key

It very much is possible to prevent an agent from having access to a key. For example, local encryption, Yubikey or other hardware device, or just running the agent in an isolated environment.