The point here is that I could sign any email as long as I control the address. The fact that an email is signed does not mean it's to be trusted. Same with https.
That is not what the comment says. The comment says:
but all these scams would not work in a world where authors and publishers only trust signed e-mails.
Not that people will take the time and effort to verify the signatures. Not to mention that you can still call them and say "eeeh I'm Jones, you know, I just had to renew my signature, so it won't check, but it's me. bye"
Comments
This analogy is flawed in two points:
1. Let's Encrypt isn't useless
because
2. With certificates you can be sure, the message you received, is from the certificate owner. This applies to websites and emails.
The point here is that I could sign any email as long as I control the address. The fact that an email is signed does not mean it's to be trusted. Same with https.
From where would you get the private PGP key of the person who owns the email address?
That is not what the comment says. The comment says:
Not that people will take the time and effort to verify the signatures. Not to mention that you can still call them and say "eeeh I'm Jones, you know, I just had to renew my signature, so it won't check, but it's me. bye"