One is a digital fingerprint, effectively a has of the public key that you can validate over the phone or in some other method. (This is a one way method where the fingerprint can not be used to regenerate the public or private key) The other is peer validation. peer validation relly's upon you trusting a third party to act as an authority on the person you are sending data to.