Re: The introduction problem, was Thinking outside the box
Paul Smith <[email protected]> Tue, 19 Mar 2013 16:26:09 +0000
| Newsgroups | gmane.ietf.asrg |
|---|---|
| Message-ID | <[email protected]> |
On 19/03/2013 16:01, Dave Crocker wrote: > > > On 3/18/2013 1:52 PM, Paul Smith wrote: >> But, if I tell you (and only you) my "public" key, and you sign/encrypt >> your message to me with MY public key, then I can be fairly sure that >> the signed messages I receive aren't spam. > > This comes close to saying "first we need a miracle"... > > OpenPGP and S/MIME have had roughly 20 years to succeed. Their > patterns of actual success are quite notable, but have consistently > been for relatively small, homogeneous groups. Of course, there is a HUGE difference between a PGP or S/MIME public key and a simple text password. That is one big difference between PGP & S/MIME and something simpler. I could be on the phone to someone, and they ask me for my email address to send me details, I tell them it and I add "and my email key is 'bibble'". Then, when they send the message to me, their email client asks for that, and hey presto, I get the message. Try doing that with a PGP public key... Yes, PGP & S/MIME are cryptographically much more secure, but people don't understand them. People do understand passwords. In my experience, that is the prime reason why PGP & S/MIME aren't widely used. If a user could set a 'generic password' in their email software and an optional individual password against entries in their email address book, it would be well within most users' understanding. Most users would not be able to generate a PGP key, never mind know what to do with it after that. (as someone close to here suggested recently: most users are idiots) Yes, to work properly, a 'password' system would need wide implementation support - but we were asked to 'think outside the box'... Also, I'm not entirely sure about the scale of the 'introduction problem' with this scheme either. How many people (other than spammers) are just going to email randomly to an email address they guess? You're going to get the email address from somewhere. That "somewhere" can tell you the key as well. (Yes, this means that if it's on a website, potentially a spammer could scrape the email & key from there together, but it's a lot more complicated to automatically link two separate pieces of text than to identify an email address - also they'd potentially have to do it frequently to keep up to date with the password which will likely change much more often than the email address) - Paul Smith Computer Services Tel: 01484 855800 Vat No: GB 685 6987 53