Earlier quoted context omitted.
> As it is, there is not even a way for a known email sender to securely introduce an unknown email sender. You know, the way that regular human people normally are able to transfer identities from one to the other. That's exactly what PGP's web of trust model is for. Someone you know, and trust, can sign and send you a public key of someone that they trust. This new key will be automatically trusted in your trust st…
Well, yeah, we should use preexisting standards and OpenPGP would be perfectly fine here and is probably the best choice. That is a wheel we do not need to reinvent. But the actual system used to do the signatures and keep track of the reputation is the last thing we should be thinking about at this point. We should instead concentrate on how to create a system that the majority of people can use and understand. We s…
The other option, of course, is to design a trustless system, like BitCoin, but that has its own problems.