@Dietrich T. Schmitz * Your Linux Advocate
If a user is not in your 'web of trust', then you can safely assume the email was totally unsolicited.
True, but an unauthorized user can get into your "web of trust". That's the problem. The GPG uses information that the user gives it to create a digital signature. I could create a digital signature today identifying myself as Dietrich T. Schmitz * Your Linux Advocate. That doesn't make me you...thankfully.
Reading is fundamental
So is understanding concepts you pretend to know about.
The best of ZDNet, delivered
ZDNet Newsletters
Get the best of ZDNet delivered straight to your inbox



