Re: Key lookup service via draft-bhjl-x509-srv-00
Wei Chuang <[email protected]> Wed, 23 Mar 2016 16:00:46 -0700
| Newsgroups | gmane.ietf.smime,gmane.ietf.x509 |
|---|---|
| Message-ID | <CAAFsWK1ySBR0g8ETO1rCCS=AY386-fZdcxBGjU3RV1Kwfs7m4w@mail.gmail.com> |
On Wed, Mar 23, 2016 at 3:23 PM, John R Levine <[email protected]> wrote: > Could Yahoo! (in this example) not provide a means for their users to >> update the key lookup service? As the user is authenticated through their >> UI, he or she could upload the keys they want in a secure way. >> > > Sure, and then Yahoo would serve the keys the users provide. > > R's, > John > > PS: Except for the MITM keys intalled by government order or rogue > employees. > If this is part of the threat model, Coniks has some ideas about auditing key services against what they term equivocation or presenting different keys to different users. The other aspect albeit in the far future one could try to replicate what has been done with WebPKI which in my opinion has been effective against those threats, and create a broad trusted anchor eco-system with strong enforcement. -Wei _______________________________________________ smime mailing list [email protected] https://www.ietf.org/mailman/listinfo/smime