Where the four minutes go
Installation is excluded from the count, because it happens once and this check happens many times. What remains is five short pieces of work, and only one of them is the check itself.
- Find the key where the market publishes it. Getting to that page eats most of the first minute.
- Import it. One command, or one menu item, and the tool confirms it took.
- Read the fingerprint the tool prints back. Forty hexadecimal characters, laid out in ten groups of four.
- Compare all ten groups against the published copy, left to right, out loud or with a finger on the screen.
- Decide. Either every group matched or the check failed, and there is no third outcome.
The comparison in step four takes under a minute. Everything around it is navigation, and navigation is exactly the part that shrinks once you know where things live.
What four minutes of comparison buys you
The only answer this subject has to the question of who you are dealing with. Counting characters, checking the alphabet and comparing prefixes all describe a string. A signature describes whoever holds a key. The forty character fingerprint is the number that settles it, and four minutes is the full retail price.
It also repairs the weak point in every address check. Twelve matching characters proves two strings are the same string and proves nothing about whether that string was ever the market's. If your reference copy arrived inside a signed message you verified, the address comparison inherits that strength. If it did not, you are comparing a forgery against itself with great care.
Set the price against what it covers. Four minutes against a deposit, against an account, against a conversation naming things you would rather not have named anywhere. No other check on this site has that ratio.
Why people think four minutes is forty
Because they have never timed it. PGP carries a reputation earned in the 1990s, when the tooling was hostile and the documentation worse. People picture an afternoon of reading, postpone it, and a postponed check never happens. The reputation costs more than the work does.
The second error happens inside the four minutes. People read the first group and the last group and call it done. That is the address mistake wearing different clothes, and it fails for the same reason: the ends are where anybody building a fake aims their effort. A fingerprint is compared in full or it is not compared.
A third habit worth breaking is verifying once and never again. A key that checked out last year checked out last year. At this price the check can be repeated whenever a message actually matters.
What pushes four minutes down to one
Repetition does most of it, and nothing about it needs to be done in a hurry. The second attempt costs half the first. By the fifth you know which page holds the key, which command imports it and what correct output looks like, and the whole job runs under a minute.
Tooling finishes the job. A client that checks a signature and shows a verdict removes the manual comparison, at which point the number stops being minutes and becomes one click. What it never becomes is zero, because somebody still had to obtain the right key at the start, and that step cannot be automated away by anyone.
Questions people ask
Do I have to check the key every single time?
No, though it is worth repeating whenever the stakes change. Importing is a one off cost and the comparison is the part you repeat.
What if one group of four does not match?
The check failed, and nothing else on the page matters after that. A near match is a fail, because a fingerprint carries no partial credit.
Is four minutes realistic for a beginner?
For the comparison itself, with the tool already installed, yes. Installing it the first time is a separate job and is deliberately not counted in the four.