Where are the security details published? I think that's what we all want to see... On top of this....I think this is cool in theory but bad in practice. The assumption that Root CA's are trustworthy is already hard enough to make, how do I know that Maria is actually Maria? How will you verify that ``Maria'' actually owns that twitter, github, gmail. Maybe it is possible to devise some type of scheme for those sites…
> confirmed they're all her, using GnuPG to review a signed tweet and gist she posted.
So it sounds like it you believe in GPG as a viable method of id, there's no reason not to trust this.