Re: The introduction problem, was Thinking outside the box

Paul Smith <[email protected]> Tue, 19 Mar 2013 17:50:48 +0000
Newsgroups gmane.ietf.asrg
Message-ID <[email protected]>
On 19/03/2013 16:52, John Levine wrote:
>> Of course, there is a HUGE difference between a PGP or S/MIME public key
>> and a simple text password.
> Not really.  In both cases, key distribution makes them unusable at
> large scale.
Does it?

This is the bit I'm struggling with.

I don't want 'random' people to email me. In fact I don't know anyone 
who wants random people to email them.

I do want my friends to email me, I do want people who've seen my 
website to email me with questions, I do want Amazon/Paypal/ASRG/etc to 
email me (because I've signed up to those services), if I was an 
professor, I may want people who've read one of my papers to email me, 
or if I was a big company, I may want someone who has seen my adverts to 
email me.

With all those groups of people, I can easily envisage a simple way of 
getting a key to them.

(I can also see a way of getting a PGP key to them as well, but it's not 
quite a simple, because PGP keys are a lot bigger, and more complex to 
generate and manage. Also, remember we're talking 'design email from 
scratch' here. PGP is a 'bolt on' to existing email, so current email 
works without it, so inertia will restrict its use, and it's complexity 
will help that inertia).

There wouldn't need to be a big infrastructure for key distribution, 
just as there is no infrastructure for email address distribution.

If I want someone to be able to email me, I currently have to tell them 
my email address. In my 'brand new email way', I just have to tell them 
my 'key' as well. I can think up a new notation as well: 'my email 
address is [email protected]/mailme'. There, that's the key distribution 
problem sorted :-).




-

Paul Smith Computer Services
Tel: 01484 855800
Vat No: GB 685 6987 53