this post was submitted on 10 Mar 2025
9 points (90.9% liked)
cybersecurity
3861 readers
2 users here now
An umbrella community for all things cybersecurity / infosec. News, research, questions, are all welcome!
Community Rules
- Be kind
- Limit promotional activities
- Non-cybersecurity posts should be redirected to other communities within infosec.pub.
Enjoy!
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
PGP keys gain trust the longer they're used. But the likely-hood that they've been compromised also increases with time. I wouldn't say they get "less secure" with time. Also, you can very easily create a new identity under the same PGP key, and revoke a previous identity. Additionally, you can certify other's keys by signing it with your own, increasing the WOT (web of trust) with the key--asserting that the key does in fact belong to the correct person.
The keys are a bit more dynamic than you're giving them credit for.
There's also F/OSS which has been designed to alleviate some of the usability issues with PGP keys, mainly Keybase.