| ▲ | gonzalohm 2 days ago | ||||||||||||||||
You visit the bank in person and the bank gives you the keys in a flash drive, QR code, printed paper, ... Then you go home and install the keys | |||||||||||||||||
| ▲ | coldpie 2 days ago | parent | next [-] | ||||||||||||||||
So, you're right that this does work in theory, but it obviously doesn't scale, right? We can't have every person physically go to every storefront they want to purchase something from and then drive home with a USB stick. What if I in Minnesota want to buy something from Florida or France? The role CAs play is to be a trusted identity verifier so we don't have to have millions of people driving around to do key exchanges in person. | |||||||||||||||||
| |||||||||||||||||
| ▲ | mahboi 2 days ago | parent | prev [-] | ||||||||||||||||
People don't really know how to install SSL certs, it's intentionally not easy especially on phones, and it's not clear that what they're installing only affects the bank. But yeah, the industry could make this semi-easy if there were a real need. | |||||||||||||||||