Earlier quoted context omitted.
> I think Keybase.io is a pretty good solution to the problem of key ownership. You can confirm the identity of anyone's Keybase key by comparing the fingerprint to one listed in any one of several "public" sources: Twitter, Github, Reddit, and even Hacker News. Doesn't that undermine the whole decentralized web of trust concept? All those services are operated by US companies - or what if someone simply compromised…
> Doesn't that undermine the whole decentralized web of trust concept? All those services are operated by US companies - or what if someone simply compromised Keybase itself? Ideally: Nothing. Keybase refers to other sources. I.e. a page on GitHub woth username and key fingerprint. So if keybase is compromises those links miss and it's no prove.
Re: Fake Linus Torvalds' Key Found in the Wild, No More Short-IDs
#131In reality some people stores their private keys there ('encrypted' according to them) so it can be stolen when they're compromised.