Verifying Public Keys without Trust: How Anonymity Can Guarantee Data Integrity

Lachlan J. Gunn, Andrew Allison, Derek Abbott · arXiv (Cornell University) · 2016

Despite the inroads that public-key cryptography has made on the web, the difficulty of key management has for the most part kept it out of the hands of the general public. With key-distribution software for PGP beginning to natively support the anonymizing service Tor, we describe a protocol to take advantage of this, allowing users and identity holders to detect malicious keyservers with an known and arbitrarily small probability of failure, allowing users to safely exchange public keys across the internet without the need for certificate authorities.

Read the paper · More papers on PaperTik