Post
Topic
Board Service Announcements
Re: [ANN] bitaddress.org Safe JavaScript Bitcoin address/private key
by
shorena
on 26/11/2016, 06:04:57 UTC
I think you have to add his PGP key to your keyring, or you have to sign his key first.

Yeah he has to sign my key or Web of Trust

No they dont have to and they should not as they are unable to actually verify your identity[1]. The important part is that signature is valid, which it is:
"gpg: Good signature from "pointbiz <pointbiz@bitaddress.org>""

Whether or not the key should be trusted has nothing to do with the verification of the code, its about verification of the key used to sign. If you just not want to see the message, sign the key locally with --lsign-key.


[1] I guess it depends how you use the WoT here.