How bad is it to make someone else think that a key is yours, when it actually is not? I.e. you have no idea what the private part is. [...] This could mean that a message signed by someone else might appear to be signed by you. But that's not so significant, as you could have achieved the same effect just by copying the plaintext of the message to be signed and signing it with one of your own keys.