Re: looking for keys under the lamppost, was limitations of reputation
"John Levine" <[email protected]> 24 Mar 2013 18:28:16 -0000
| Newsgroups | gmane.ietf.asrg |
|---|---|
| Message-ID | <[email protected]> |
>I believe it would help with joe jobs (are they still much of a >problem? I haven't seen one in a while) and phishing, knowing that msg >from your bank is really from your bank with some confidence. Banks can already put DKIM signatures on their mail to prove who sent it, and many do. As is invariably the case, the crypto is the easy part, building the environment to use the crypto in a way that works for civilians is the hard part. >Unless we were willing to go the certificate authority route at least >as originally conceived -- to get my first SSL cert I had to submit >Dun & Bradstreet info for my company and enough info for the CA to >check the info really was from a duly authorized officer of the >corporation etc. That's more or less what you have to do for a green bar cert. >Today I believe you only have to be able to fog a mirror. That's for a regular cert, and the fog can be from your ventilator. But people are still phished by spam pointing to fake sites with no SSL at all. Again, it's the user environment part that's hard. R's, John - This is the asrg mailing list. To change your subscription settings, see http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org