Chains of trust vs. PKI

Paul Crowley <[email protected]>
Newsgroups gmane.mail.ng
Message-ID <87hdy973ib.fsf_-_@saltationism.subnet.hedonism.cluefactory.org.uk>
Resting our whole authentication framework on PKI isn't the right way
to go about things.  Read Ellison and Schneier, "Ten Risks of PKI":

http://www.schneier.com/paper-pki.html

I would much rather see an SPKI-like approach to naming, in which we
use local information to bind locally meaningful names to public
keys.  This is a far better fit to practical security problems.  At
the very least, if you can persuade yourself to think the SPKI way for
a moment it will give you an entirely different perspective on many
issues to do with naming.

See also Zooko's triangle:

http://zooko.com/distnames.html
-- 
  __  Paul Crowley
\/ o\ [email protected]
/\__/ http://www.ciphergoth.org/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.