Re: The introduction problem, was Thinking outside the box
Dave Crocker <[email protected]> Tue, 19 Mar 2013 09:01:25 -0700
| Newsgroups | gmane.ietf.asrg |
|---|---|
| Organization | Brandenburg InternetWorking |
| Message-ID | <[email protected]> |
On 3/18/2013 1:52 PM, Paul Smith wrote: > But, if I tell you (and only you) my "public" key, and you sign/encrypt > your message to me with MY public key, then I can be fairly sure that > the signed messages I receive aren't spam. This comes close to saying "first we need a miracle"... OpenPGP and S/MIME have had roughly 20 years to succeed. Their patterns of actual success are quite notable, but have consistently been for relatively small, homogeneous groups. One can debate plausible explanations for this basic limitation, but the raw statistic is clear and should be compelling: Achieving large-scale, per-person authentication and confidentiality among random folk who exchange mail is, so far, not possible. The track record in trying to provide this capability makes clear that any future success here demands true innovation and considerable caution in the expectations for success. Efforts are far more likely to fail than to succeed. There is some question as to whether per-person authentication and confidentiality mechanisms are at all possible. Certainly the 'usability' design requirements are not yet well understood, either for end-users or for service operators. Any discussion about per-person authentication or confidentiality needs to start with careful attention to both the technical requirements and the very serious human factors constraints. > Theoretically we can stop email forgery (DKIM, SPF, cryptographic Theoretically, we can /not/ stop email forgery. We can limit the utility of certain forgery scenarios, but that's quite different. Any discussion about 'stopping' forgery needs to carefully consider a range of reasonable scenarios and the ability or inability of specific mechanisms to prevent those scenarios. It also needs to start with the recognition that forgery hasn't been stopped in the physical world, and then it needs to explain why the online world is going to have a different rack record... d/ -- Dave Crocker Brandenburg InternetWorking bbiw.net