Quote:
Originally posted by Sajma NiGHTSFTP: Digital signatures can't really be "removed" by anyone -- they're just data that can be verified using a public key. The rating system you proposed has the problem that a malicious user could create a high rating for a file they like and sign it with a bunch of different keys, so it looks like many different users rating the file. It's not clear how to solve this problem.
... |
What about filtering the ratings?
Like: Search-> Category -> Rated 7 or better -> "Trusted Keys Only"
And you could have a small (personal) trusted key database.
Add ability to export, import, merge the key databases. (Trade em with your friends!).