Re: The introduction problem, was Thinking outside the box
Paul Smith <[email protected]> Tue, 19 Mar 2013 17:50:48 +0000
| Newsgroups | gmane.ietf.asrg |
|---|---|
| Message-ID | <[email protected]> |
On 19/03/2013 16:52, John Levine wrote: >> Of course, there is a HUGE difference between a PGP or S/MIME public key >> and a simple text password. > Not really. In both cases, key distribution makes them unusable at > large scale. Does it? This is the bit I'm struggling with. I don't want 'random' people to email me. In fact I don't know anyone who wants random people to email them. I do want my friends to email me, I do want people who've seen my website to email me with questions, I do want Amazon/Paypal/ASRG/etc to email me (because I've signed up to those services), if I was an professor, I may want people who've read one of my papers to email me, or if I was a big company, I may want someone who has seen my adverts to email me. With all those groups of people, I can easily envisage a simple way of getting a key to them. (I can also see a way of getting a PGP key to them as well, but it's not quite a simple, because PGP keys are a lot bigger, and more complex to generate and manage. Also, remember we're talking 'design email from scratch' here. PGP is a 'bolt on' to existing email, so current email works without it, so inertia will restrict its use, and it's complexity will help that inertia). There wouldn't need to be a big infrastructure for key distribution, just as there is no infrastructure for email address distribution. If I want someone to be able to email me, I currently have to tell them my email address. In my 'brand new email way', I just have to tell them my 'key' as well. I can think up a new notation as well: 'my email address is [email protected]/mailme'. There, that's the key distribution problem sorted :-). - Paul Smith Computer Services Tel: 01484 855800 Vat No: GB 685 6987 53