Comment 4 for bug 374594

Revision history for this message
Martin Owens (doctormo) wrote :

The add key command line is a construct which was created to allow people who had checked a key's trust online or through some other tool to be able to add a key. It's not supposed to be the whole system of key management.

A very important part is making sure that the user trusts _this person_ who owns that key. We can't go running around assuming that they do, not even warning them.

`gpglist 170EBB2F` gives me useful information about who has signed my trusted key, information worth knowing as you can score a key that way.

You'll notice on my key I have a number of trusted parties and a photo id (which includes a jpeg of what I look like) all useful informations. But on Launchpad we have more information, users location, karma, photo, and other useful things which can be used to just confirm that the person is who they say they are.