Earlier quoted context omitted.
Yeah, web of trust gives me the option to manually decide, every time, if the chain(s) of trust looks "good enough" for me to trust the other party. There are two problems with this: 1. This is a ton of work and a lot of guesswork even for educated individuals. I end up looking at either explicit chains of trust (I trust Bob and he trusts Alice and she says that this is definitely my bank's website) or some random va…
> I guarantee you a month later Google and Apple and Microsoft will become the de facto CAs Except that none of those companies bother verifying one's identity if you're not actually paying for their services. > and see if one of them vouches for their banking website. In that scenario, could I not just verify the bank's public key when I'm physically in one of their branch locations while opening an account? They co…
I'm sure in this scenario, those companies will be delighted to step fully into the role of CA including accepting money for identity vouching.
> In that scenario, could I not just verify the bank's public key when I'm physically in one of their branch locations while opening an account? They could also verify my public key at the same time. That would allow for a direct line of trust. The same could apply to any company one deals with.
No. The same couldn't apply to any company. My primary bank is online only. And how many times have you actually walked into an Amazon office? Or Paypal? Are people in Ohio supposed to fly to San Jose to get Paypal's public key when they create an account? Or are we going to wait for the post office to deliver a physical copy of Paypal's public key (and we'll just trust that whole transaction couldn't be compromised). Physical key exchange is simply not practical in most cases.