Where are the security details published? I think that's what we all want to see... On top of this....I think this is cool in theory but bad in practice. The assumption that Root CA's are trustworthy is already hard enough to make, how do I know that Maria is actually Maria? How will you verify that ``Maria'' actually owns that twitter, github, gmail. Maybe it is possible to devise some type of scheme for those sites…
> how do I know that Maria is actually Maria? How will you verify that ``Maria'' actually owns that twitter, github, gmail. > confirmed they're all her, using GnuPG to review a signed tweet and gist she posted. So it sounds like it you believe in GPG as a viable method of id, there's no reason not to trust this.
That's the part where you trust the PKI, and that part is easily subverted, breaking the trust of the entire system.
If they were using the inherent properties of maria's key (e.g. the fingerprint), then they wouldn't need this whole silly website and username database.
Maybe this should be an offline tool that just goes and fetches tweets and gists so we don't have to trust them. You could add friend mappings with key fingerprint + nickname.