In a fully decentralized environment, you would need to somehow know who to trust and make some karma/feedback in a decentralized way.
Given that PGP's web of trust never really caught on, I am not sure if this would work.
But maybe it would and I am just too pesimistic.