> Yeah, about that. I never ever ever successfully used the WoT to validate a public key. If you ever installed a Debian package then you did. A long-term identity as "Bob Jones" might not be terribly useful - but that's not the kind of long-term identity we care about a lot in real life either. A long-term identity as "Debian release manager" or "Signatory on bank account xyz" or even "Wikileaks committee member" is…
You understand the difference between a lone hacker as an APT vs a state level threat as an APT. That distinction is huge and chooing not to defend yourself against one or the other may allow for huge convenience gains at the cost what is to many a purely hypothetical notion of security. Can we improve the tools and techniques we have enough so they are convenient enough to not have to make such a choice?
Once you step beyond that, there are no convenient options (or to put it differently, all convenient options come with risks that are more-or-less as big as the CA system). E.g. compromising Signal's central servers is probably not substantially harder than compromising a CA, and I simply don't trust that a system that does automated key exchange on first use (trusting the servers) will be able to avoid downgrade attacks by a compromised server. I think to a certain extent usability issues are inherent - if you are unwilling to trust any centralized identity services then you have to show key fingerprints and rely on the user to verify them themselves, there's no third option. At the same time I think we can and should do a lot better than current GPG.