I've now done enough stories where PGP keys feature as one aspect of identity verification to where I can say for certain: fucking everyone is bad at PGP
-
Show this thread
-
The best PGP key management / consistent usage I've seen so far was the Dread Pirate Roberts', and in the end the existence of his private key on his laptop became part of the case against him
5 replies 44 retweets 198 likesShow this thread -
-
Replying to @emptywheel @matthew_d_green
In trial, they matched the private key found on his laptop to various DPR Silk Road forum postings that were PGP-signed.
1 reply 0 retweets 5 likes -
Replying to @sarahjeong @matthew_d_green
Sorry, that part I knew. I'm curious why you said he had best key management?
1 reply 0 retweets 1 like -
Replying to @emptywheel @matthew_d_green
Everyone else I’ve looked at seem to have lost a key / multiple keys, were careless about making sure to revoke old or lost keys in key pools / did not regularly post fingerprints in easy to find places
1 reply 0 retweets 9 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.