Re: The introduction problem, was Thinking outside the box

Paul Smith <[email protected]> Tue, 19 Mar 2013 16:26:09 +0000
Newsgroups gmane.ietf.asrg
Message-ID <[email protected]>
On 19/03/2013 16:01, Dave Crocker wrote:
>
>
> On 3/18/2013 1:52 PM, Paul Smith wrote:
>> But, if I tell you (and only you) my "public" key, and you sign/encrypt
>> your message to me with MY public key, then I can be fairly sure that
>> the signed messages I receive aren't spam.
>
> This comes close to saying "first we need a miracle"...
>
> OpenPGP and S/MIME have had roughly 20 years to succeed.  Their 
> patterns of actual success are quite notable, but have consistently 
> been for relatively small, homogeneous groups.

Of course, there is a HUGE difference between a PGP or S/MIME public key 
and a simple text password.

That is one big difference between PGP & S/MIME and something simpler.

I could be on the phone to someone, and they ask me for my email address 
to send me details, I tell them it and I add "and my email key is 
'bibble'". Then, when they send the message to me, their email client 
asks for that, and hey presto, I get the message.

Try doing that with a PGP public key...

Yes, PGP & S/MIME are cryptographically much more secure, but people 
don't understand them. People do understand passwords. In my experience, 
that is the prime reason why PGP & S/MIME aren't widely used.

If a user could set a 'generic password' in their email software and an 
optional individual password against entries in their email address 
book, it would be well within most users' understanding. Most users 
would not be able to generate a PGP key, never mind know what to do with 
it after that. (as someone close to here suggested recently: most users 
are idiots)

Yes, to work properly, a 'password' system would need wide 
implementation support - but we were asked to 'think outside the box'...

Also, I'm not entirely sure about the scale of the 'introduction 
problem' with this scheme either.

How many people (other than spammers) are just going to email randomly 
to an email address they guess? You're going to get the email address 
from somewhere. That "somewhere" can tell you the key as well.

(Yes, this means that if it's on a website, potentially a spammer could 
scrape the email & key from there together, but it's a lot more 
complicated to automatically link two separate pieces of text than to 
identify an email address - also they'd potentially have to do it 
frequently to keep up to date with the password which will likely change 
much more often than the email address)



-

Paul Smith Computer Services
Tel: 01484 855800
Vat No: GB 685 6987 53