{"type":"rich","version":"1.0","author_name":"npub1kf0ppcjaguxekg24yx6smgxlu73qn0k8lm0t2wrqc0scpl7u3sgsmf3f58","author_url":"https://nostr.ae/npub1kf0ppcjaguxekg24yx6smgxlu73qn0k8lm0t2wrqc0scpl7u3sgsmf3f58","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2014-09-15\n📝 Original message:On Mon, Sep 15, 2014 at 3:23 AM, Thomas Zander \u003cthomas at thomaszander.se\u003e wrote:\n\u003e Any and all PGP related howtos will tell you that you should not trust or sign\n\u003e a formerly-untrusted PGP (or GPG for that matter) key without seeing that\n\u003e person in real life, verifying their identity etc.\n\nSuch guidelines are a perfect example of why PGP WoT is useless and\nstupid geek wanking.\n\nA person's behavioural signature is what is relevant.  We know how\nSatoshi coded and wrote.  It was the online Satoshi with which we\ninteracted.  The online Satoshi's PGP signature would be fine...\nassuming he established a pattern of use.\n\nAs another example, I know the code contributions and PGP key signed\nby the online entity known as \"sipa.\"  At a bitcoin conf I met a\nperson with photo id labelled \"Pieter Wuille\" who claimed to be sipa,\nbut that could have been an actor.  Absent a laborious and boring\nsigned challenge process, for all we know, \"sipa\" is a supercomputing\ncluster of 500 gnomes.\n\nThe point is, the \"online entity known as Satoshi\" is the relevant\nfingerprint.  That is easily established without any in-person\nmeetings.\n\n-- \nJeff Garzik\nBitcoin core developer and open source evangelist\nBitPay, Inc.      https://bitpay.com/"}
