Nostr and the Web of Trust

The Idea That Waited for the Right Internet

Amiar

9/21/202612 min read

Before social media algorithms, before centralised platforms, and before our feeds were selected by proprietary systems, there was already a proposal for building trust in a distributed way.

It was called Web of Trust.

The idea was simple.

Instead of having a central authority declare that a given identity was legitimate, people could attest to or endorse one another. I trust A. A trusts B. B knows C. The existence of these relationships could help me form an opinion about C.

There was no need for a central authority.

Trust could be built through the network itself.

And there is an important historical detail here: the Web of Trust predates the social networks we know today.

It did not emerge as a response to Facebook, Twitter, or Instagram. The idea was already being explored in the context of public-key cryptography when the social Internet was still far from reaching the scale it would eventually achieve.

The Web of Trust simply did not take off as a widespread model of use.

Social networks ended up solving the problem in a different way: they concentrated identity, discovery, relationships, publishing, and reputation within centralised platforms.

Facebook became the simple way to find people, add friends, follow activity, and build a network. Other platforms did the same, with different models.

And for years, it seemed that this was simply the natural way to build a social network on the Internet.

This is precisely where Nostr (https://nostr.com/) becomes interesting.

Nostr did not invent the Web of Trust.

It recovers an idea that already existed and attempts to put it into practice in a very different technological and social context.

Not because it is simply a modern version of the Web of Trust.

It is not.

But because it brings together some of the conditions that the idea of a distributed trust network lacked for a long time: persistent cryptographic identity, explicit social relationships, interoperability between applications, and an architecture that does not depend on a single platform.

And perhaps it is this combination that makes it possible to recover an idea the Internet tried to realise decades ago.

It Is Not a New Idea

This is where we need to start.

The Web of Trust did not originate with Nostr.

One of its best-known forms emerged in the context of PGP, associated with public-key cryptography.

The principle was precisely to avoid the need for a central authority to establish the authenticity of an identity.

Instead of automatically trusting a certificate authority, users themselves could verify and endorse other people's keys.

Trust would be built through these relationships.

If I verified the key of someone I trusted, I could attach some value to that endorsement. If that person had endorsed another identity, that relationship could also provide information.

It was an attempt to turn trust into a distributed property of the network.

On paper, it is an extraordinarily powerful idea. In practice, it had a problem.

People had to understand too much in order to benefit from it:

The Problem Was Not the Web of Trust

It is tempting to say that the Web of Trust “failed.”

But that oversimplifies the story.

The problem was not necessarily the concept.

It was the distance between the concept and the user experience.

The classic Why Johnny Can't Encrypt study, published by USENIX in 1999, specifically tested the use of PGP 5.0 by people without advanced knowledge of cryptography. Most participants were unable to correctly complete a signing and encryption task within the 90-minute test. The researchers identified problems with the interface, understanding of the public-key model, and trust management.

There is a particularly revealing detail in the study.

Key-management functions — including the construction of the Web of Trust itself — could overwhelm users with information before they were even able to perform the main task correctly.

In other words, the technology asked people to understand the infrastructure before they could simply use it.

That is a difficult inversion to sustain.

The user wanted to send a message.

The system wanted them to understand:

  • public keys;

  • private keys;

  • signatures;

  • fingerprints;

  • trust levels;

  • certification;

  • keyrings;

  • revocation;

  • relationships between identities.

It was not a question of people being incapable of understanding cryptography.

It was a question of there being no sufficiently strong reason to ask them to understand it before they could do what they actually wanted to do.

Later studies continued to find similar difficulties in using encryption and trust systems, despite improvements in interface design.

The lesson is not that people do not want security.

It is that security needs to disappear into the experience.

What Has Changed Since Then?

The Internet changed.

When PGP began trying to popularise these mechanisms, the social Internet was still taking shape.

Today, virtually everyone intuitively understands a series of digital relationships:

following someone.

being followed.

blocking.

muting.

reporting.

recommending.

sharing.

belonging to a community.

We do not need to explain the concept of “following” to someone who uses social media.

It is an acquired social behaviour.

And this is precisely where Nostr becomes interesting.

Instead of starting with the question:

“Do you want to build a Web of Trust?”

it starts with the question:

“Who do you want to follow?”

The difference seems small.

In reality, it is fundamental.

Nostr Starts with the Relationship

Nostr is an open communication protocol.

Users have a cryptographic identity, and published events are signed by that identity. Events can be distributed through different relays rather than relying on a single server.

But the user does not need to think about all of this.

They can simply publish a note.

They can follow someone.

They can reply.

They can receive a reply.

They can discover someone new through someone they already follow.

And, by doing so, they are building something very important:

a graph of relationships.

A Web of Trust can emerge from that graph.

The user does not need to be aware that they are participating in a distributed trust system.

They are simply relating to other people.

Nostr Is Not a Blockchain. Is it Web3?

This is where it is worth clearing up a common misconception.

Nostr is not a blockchain.

There is no Nostr blockchain where every post is recorded in a global ledger. There is no global consensus mechanism ordering every event. Data is transmitted and stored through independent relays, while identity and events are protected by public-key cryptography.

But that does not mean Nostr falls outside what is commonly understood as Web3.

If we understand Web3 not as a synonym for blockchain or cryptocurrency, but as a broader vision of a more decentralised, interoperable Internet oriented towards user ownership and control of identity and data, then Nostr clearly fits within that logic.

In fact, this distinction is part of what makes Nostr interesting.

Web3 does not necessarily have to mean blockchain.

A blockchain is a technology.

Web3 is a broader set of ideas about how the Internet can be structured.

Nostr seeks to apply some of those ideas without needing to put all social communication on a blockchain.

And perhaps that is one reason why its architecture is relatively simple: instead of trying to solve identity, communication, storage, and consensus through a single infrastructure, it separates the problems.

Keys for identity.

Events for content.

Relays for transmission and storage.

Clients for experience.

And relationships between users for building the social layer.

The Social Graph as a Signal of Trust

Imagine a person named Alice.

Alice follows one hundred people.

Of those one hundred people, twenty follow Bob.

Alice may not know Bob.

But Bob is not necessarily a complete stranger.

There is a relationship between Bob and several people Alice has chosen to follow.

That relationship can be information.

Now imagine that five of the people Alice particularly trusts endorse Bob through their own relationship with him.

That is another piece of information.

If those people regularly interact with Bob, that is another signal.

If Bob is followed by thousands of accounts completely unknown to Alice, that is also information — but of a different kind.

None of these signals proves that Bob is trustworthy.

But they can help Alice decide whether to pay attention.

That distinction matters.

A Web of Trust does not need to answer “trustworthy” or “untrustworthy.”

It can provide context.

It can rank signals.

It can help reduce noise.

It can make a social network navigable without requiring a central authority to make every decision.

And this is where the verb endorse starts to become important.

Endorsing does not necessarily mean saying:

“This person is absolutely trustworthy.”

It can simply mean:

“I put my own identity behind this relationship.”

The value of an endorsement comes, in part, from who makes it.

And that endorsement can, in turn, become a signal for other people.

That is how a trust network grows.

Endorsing Is Not Certifying

There is an important difference between these concepts.

A certificate authority can state that a given identity meets certain requirements.

A user can attest that a given identity corresponds to someone they know.

And someone can endorse a person, project, piece of content, or relationship because they consider it worthy of attention or trust.

These are different acts.

A trust network can use all of these signals without turning them into a single universal measure.

That plurality is precisely what makes the concept interesting.

We do not need to replace a central authority with a new central authority.

We can build trust through relationships between people.

Nostr Is Already Formalising This Idea

This is no longer merely a theoretical possibility.

The Nostr ecosystem is developing specific mechanisms for working with trust derived from relationships.

NIP-85, for example, defines Trusted Assertions.

The idea is to allow specialised services to perform calculations that would be too demanding for many clients — including Web of Trust calculations — and publish the results as signed events that clients can use.

This is particularly interesting because it does not necessarily establish a single Web of Trust.

One service can use one algorithm.

Another can use another.

One can calculate a general trust relationship.

Another can calculate a relationship personalised to the perspective of a particular user.

This opens up a possibility very different from the logic of traditional platforms.

Instead of:

“The algorithm says this person is relevant.”

we can have:

“This is one of the models through which you can interpret the network.”

There Is Not a Single Reputation

This may be one of the most important consequences.

On a centralised platform, reputation is often produced by a system the user does not control.

There is an algorithm.

That algorithm receives signals.

The algorithm decides what appears.

We see the result.

We do not even need to know exactly what the criteria were.

On Nostr, a Web of Trust can be plural.

My trust model may not be the same as yours.

I may place more trust in people I know personally.

You may give greater importance to specific communities.

Someone else may want to give greater weight to the age of an identity.

Another person may want to consider relationships between communities.

Another may simply want to know:

“How many people I follow also follow this person?”

None of these approaches needs to be universal.

And that plurality matters because trust is a contextual relationship.

We do not trust someone for everything.

We may trust someone to discuss cryptography and not trust them to recommend restaurants.

We may trust an organisation for legal information and not for medical information.

We may consider someone a good source on technology and completely ignore their opinions on another subject.

A universal reputation is therefore a simplification.

A distributed Web of Trust may represent that reality better.

Identity Stops Being an Account

Here we reach an even deeper difference.

When we create an account on a traditional social network, we usually think in terms of:

I have an account on X;

I have an account on Facebook;

I have an account on Instagram.

But the account belongs to that platform's system.

The platform controls authentication.

The platform controls the identifier.

The platform controls access.

The platform controls the infrastructure that maintains the account.

On Nostr, the logic is different.

The fundamental identity is the cryptographic key.

This means we can begin to separate concepts that, for decades, we have treated as a single thing:

identity

is not necessarily

application

and is not necessarily

server.

This Distinction Changes Everything

Imagine that we use a Nostr application for five years.

We build relationships.

We follow hundreds of people.

We publish thousands of notes.

We participate in communities.

We build a reputation.

We create references.

Other people come to recognise our identity.

Then we decide to switch applications.

In the traditional model, the question would be:

“How do I export my account?”

In the Nostr model, the question is different:

“Which application do I want to use to access my identity and my relationships?”

It is a huge conceptual difference.

The client becomes a window.

Not necessarily the house.

From Trust to Sovereignty

This is where the Web of Trust begins to meet a larger question.

If my identity can exist independently of an application...

If my relationships can be represented as interoperable data...

If different applications can interpret those relationships...

If different services can build different models of trust...

Then we begin to separate something that has been fused together for a long time:

the person

from

the platform where that person appears.

This separation is much more important than simply being able to choose between five Nostr applications.

It means that social infrastructure can begin to belong to the people who constitute it, rather than only to the company providing the interface.

The Problem Social Networks Solved — and Created

The major platforms solved an extraordinary problem.

They made it extremely easy to find people.

Create an identity.

Publish.

Follow.

Share.

Create communities.

Communicate at scale.

Their success was so great that we came to accept as natural a consequence that was not inevitable:

to participate in a digital community, we have to do so within a company's infrastructure.

And that company sits between us and our network.

Between us and our followers.

Between us and our content.

Between us and the data we produce.

Between us and our reputation.

This is extremely convenient.

But it also creates dependency.

When a Platform Decides Someone No Longer Exists

There is a question that usually arises in connection with content moderation.

But there is a question that comes before it:

who owns the social relationship?

Imagine a person who has spent ten years building a community.

They have thousands of followers.

Thousands of posts.

Conversations.

Contacts.

References.

Photographs.

Videos.

History.

A professional network.

An audience.

A reputation.

One day, the platform decides to suspend the account.

There may be legitimate reasons for moderation.

There may be contestable reasons.

There may be a mistake.

There may be a policy change.

There may be a change of ownership.

There may be a regulatory change.

There may simply be an incorrect automated decision.

The structural problem is something else:

the person may lose access to the infrastructure through which they built their digital social life.

Not because they lost their identity.

But because the platform controls access to the digital representation of that identity.

This is where the discussion about Nostr begins to move beyond the Web of Trust.

The Next Question Is No Longer Just “Who Do I Trust?”

It is:

“Who controls what I have built?”

This is the question we will leave for a future article.

Because one thing is having a portable cryptographic identity.

Another is actually being able to carry with us:

  • our posts;

  • our photographs;

  • our videos;

  • our conversations;

  • our lists;

  • our followers;

  • our communities;

  • our contacts;

  • our histories;

  • the relationships we have built over years.

And here we encounter a fundamental distinction.

Identity portability is not the same as data portability.

We can have a public key that identifies us and still remain dependent on a platform to store much of what we have built.

Nostr brings us closer to the first idea.

The next discussion is how far we can take the second.

From Web of Trust to a Web We Own

Perhaps this is the evolution worth following.

First, we asked:

Who can we trust?

The Web of Trust attempted to answer:

The network of relationships we build.

Or, in a language we can make our own:

Who we trust, who we endorse, and who endorses us.

Then we asked:

How can we communicate without depending on a central authority?

Open protocols sought to answer.

Now a larger question emerges:

How can we build our digital lives without handing ownership of our social identity to the platform that provides the interface?

This is where the conversation about Nostr stops being just a conversation about Nostr.

Because if an identity can be portable...

If relationships can be portable...

If reputation can be built from relationships...

If different applications can interpret the same identity...

then it becomes inevitable to ask:

what else should be portable?

That is the next discussion.

Not just identity portability.

Not just trust portability.

But the portability of our own social data.

Because one thing is choosing to leave a platform.

Something very different is being able to leave without leaving behind a part of the digital life we built there.Sim. Para fechar o artigo em inglês, acrescentaria uma nota curta e coerente com o tema, sem parecer uma chamada promocional excessiva:

Transparency is the way

If this idea resonates with you, follow us on Nostr.

Our public key:
npub1z2lrk5xwat882zhe0uqkpm6d0v5exj5pjqptkv2f896n33z6pccq9pchzh

Join the network. Endorse the connection.

Our Socials

Join our community or directly ask any question, we are happy to clarify

Book a call?

2026. All rights reserved. ThEndorSemenT is a non-profit initiative and does not constitute an investment vehicle or financial service under applicable regulations

parent organization

NEWSLETTER

IMPACT

Transparent systems that empower informed participation and shared responsibility

Institutional Support

Technology Partners

4 Incubated projects
1 Endorsed brand
€30K Funding secured

Transparency is the way