@BluesDriveAmelia PGP uses keypairs. I could steal your public key and claim it's mine, but if someone encrypts something with it and sends it to me, I still can't read it without your secret key.I haven't researched how identity management sites like that work, but maybe they make you sign something (a URL?) with your secret key and validate that against the public key to prove that you're the owner of that identity.