Skip to content

Comment on Someone is stealing unpublished book manuscripts in a phishing scamparent

Comments

The point here is that I could sign any email as long as I control the address. The fact that an email is signed does not mean it's to be trusted. Same with https.

From where would you get the private PGP key of the person who owns the email address?

That is not what the comment says. The comment says:

but all these scams would not work in a world where authors and publishers only trust signed e-mails.

Not that people will take the time and effort to verify the signatures. Not to mention that you can still call them and say "eeeh I'm Jones, you know, I just had to renew my signature, so it won't check, but it's me. bye"

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.