@jamesob@evoskuil Trusting the signer. Trusting the delivery mechanism for the public key, trusting the software used to verify the key...
There's a lot of trust baked in there. Always a question of "what's reasonable?" Or "how costly is this attack?"