logoalt Hacker News

alexjurkiewicztoday at 4:36 AM3 repliesview on HN

The Web of Trust failed for PGP 30 years ago. Why will it work here?

For a single organisation, a list of vouched users sounds great. GitHub permissions already support this.

My concern is with the "web" part. Once you have orgs trusting the vouch lists of other orgs, you end up with the classic problems of decentralised trust:

1. The level of trust is only as high as the lax-est person in your network 2. Nobody is particularly interested in vetting new users 3. Updating trust rarely happens

There _is_ a problem with AI Slop overrunning public repositories. But WoT has failed once, we don't need to try it again.


Replies

Animatstoday at 7:35 AM

> The Web of Trust failed for PGP 30 years ago. Why will it work here?

It didn't work for links as reputation for search once "SEO" people started creating link farms. It's worse now. With LLMs, you can create fake identities with plausible backstories.

This idea won't work with anonymity. It's been tried.

javascripthatertoday at 5:13 AM

Web of Trust failed? If you saw that a close friend had signed someone else's PGP key, you would be pretty sure it was really that person.