<oembed><type>rich</type><version>1.0</version><author_name>npub1kf0ppcjaguxekg24yx6smgxlu73qn0k8lm0t2wrqc0scpl7u3sgsmf3f58</author_name><author_url>https://nostr.ae/npub1kf0ppcjaguxekg24yx6smgxlu73qn0k8lm0t2wrqc0scpl7u3sgsmf3f58</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2014-09-15&#xA;📝 Original message:On Mon, Sep 15, 2014 at 3:23 AM, Thomas Zander &lt;thomas at thomaszander.se&gt; wrote:&#xA;&gt; Any and all PGP related howtos will tell you that you should not trust or sign&#xA;&gt; a formerly-untrusted PGP (or GPG for that matter) key without seeing that&#xA;&gt; person in real life, verifying their identity etc.&#xA;&#xA;Such guidelines are a perfect example of why PGP WoT is useless and&#xA;stupid geek wanking.&#xA;&#xA;A person&#39;s behavioural signature is what is relevant.  We know how&#xA;Satoshi coded and wrote.  It was the online Satoshi with which we&#xA;interacted.  The online Satoshi&#39;s PGP signature would be fine...&#xA;assuming he established a pattern of use.&#xA;&#xA;As another example, I know the code contributions and PGP key signed&#xA;by the online entity known as &#34;sipa.&#34;  At a bitcoin conf I met a&#xA;person with photo id labelled &#34;Pieter Wuille&#34; who claimed to be sipa,&#xA;but that could have been an actor.  Absent a laborious and boring&#xA;signed challenge process, for all we know, &#34;sipa&#34; is a supercomputing&#xA;cluster of 500 gnomes.&#xA;&#xA;The point is, the &#34;online entity known as Satoshi&#34; is the relevant&#xA;fingerprint.  That is easily established without any in-person&#xA;meetings.&#xA;&#xA;-- &#xA;Jeff Garzik&#xA;Bitcoin core developer and open source evangelist&#xA;BitPay, Inc.      https://bitpay.com/</html></oembed>