Re: Key lookup service via draft-bhjl-x509-srv-00

Wei Chuang <[email protected]> Wed, 23 Mar 2016 16:00:46 -0700
Newsgroups gmane.ietf.smime,gmane.ietf.x509
Message-ID <CAAFsWK1ySBR0g8ETO1rCCS=AY386-fZdcxBGjU3RV1Kwfs7m4w@mail.gmail.com>
On Wed, Mar 23, 2016 at 3:23 PM, John R Levine <[email protected]> wrote:

> Could Yahoo! (in this example) not provide a means for their users to
>> update the key lookup service?  As the user is authenticated through their
>> UI, he or she could upload the keys they want in a secure way.
>>
>
> Sure, and then Yahoo would serve the keys the users provide.
>
> R's,
> John
>
> PS: Except for the MITM keys intalled by government order or rogue
> employees.
>

If this is part of the threat model, Coniks has some ideas about auditing
key services against what they term equivocation or presenting different
keys to different users. The other aspect albeit in the far future one
could try to replicate what has been done with WebPKI which in my opinion
has been effective against those threats, and create a broad trusted anchor
eco-system with strong enforcement.

-Wei

_______________________________________________
smime mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/smime