Conversation
@jonmasters as usual, we get into the morass of key distribution, revocation, and trusting the infra. If you add a signed document like "I am userfoo@social.kernel.org" and add it to your profile, that doesn't actually certify every post you make. I can post things as any user on social.kernel.org, so I (or someone who hacks me) can impersonate anyone there.

I am currently leaning towards webfinger-level certification -- you can easily verify that mricon@kernel.org is actually monsieuricon@social.kernel.org, and I think this is good enough for most purposes.
0
0
2