\TODO{find a cite for the PGP web of trust}

The standard model for calculating trust in a decentralized network is the ``web of trust'', whose most well known implementation is for the PGP system. In the PGP web of trust, each user generates a public/private keypair using an encryption algorithm such as RSA or DSA and uploads their public key to a keyserver. Users then meet up in person and verify each others' credentials (this is colloquially known as a ``keysigning party'') and, with their own private keys, sign certifications that the key does in fact belong to the name associated with the key. These signatures are then uploaded to the public keyservers.

Given that the signatures are all on the public servers, and the list of signatures on any given key can be accessed easily, a client can generate the ``trust path'' between one person's private key and another's public: e.g., Alice has verified Bob's identity, who has verified Celine's, who has verified Dedric's, and so forth. Given the existence of enough trust paths, Alice can be reasonably convinced, even in the event of a failure in judgment (or of malice) invalidating one of the trust paths, that the key she has for Dedric belongs to the real Dedric. As used in practice, the 
