phf: for the record i think a secure and verifiable path for receiving a key of person in wot is to ssl connect to freenode using explicit server key, request
!shasum wot from assbot, download
http://files.bitcoin-assets.com/wot/wot_users.sql.gz, verify its shasum, do `zgrep -oE '\([^)]+phf[^)]+\)' wot_users.sql.gz` (or whatever nick), the second number in the grep output is going to be the key fingerprint, next grep --recv-key <fingerprint>