Re: getross - email privacy /security of system

Curt Sampson <[email protected]>
Newsgroups gmane.mail.pine.general
Message-ID <Pine.NEB.4.64.0611080916310.6451@localhost>
On Tue, 7 Nov 2006, Ross wrote:

> I do not know any of you. Yet I do know People that know me, as do you. Would 
> we be better protected if we established a network where certificate 
> authority resides in our knowledge of each other, issued as public 
> certificates?  A slow building system that can be controlled outside 
> establishments?

You have just exactly described the PGP public key infrastructure.

> Essentially a public system not only for public PGP keys, but any
> verification.

That's easy enough to do with PGP as it stands. Here's an arbitrary
"certificate" signed by me:

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

THIS IS A SAMPLE   THIS IS A SAMPLE   THIS IS A SAMPLE

I assert that I have received on 2006-11-07 from
Joe Bloggs <[email protected]> the sum of USD 0.03, which I have
agreed to return in full by 2007-03-01.

(This is a sample of a "certificate" created and signed by "me".
See the key information to find out who "I" am. This text file
could be any sort of contract.)

THIS IS A SAMPLE   THIS IS A SAMPLE   THIS IS A SAMPLE 
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (NetBSD)

iQEVAwUBRVEjwagqOkIlgIs6AQLOLggA1nRhuXCLXKmyM9c1LLGfTxzShUuvxy18
d/iu7mXoG2qqFc+f/WMcXeEOZ8kF2t1911ixcE5AXRbToryi6yVO8w1x3Y1tHlWe
bkPa0EwkJ6XNLKQ7OAZrLbn7M4Z+vXY+s9bj9maN37x4sKdGkPVdYIOF8AkNCj2p
dL9jSjDQbnSnkr5ifav/sJWeSOH7IifVKrxfsCXn3jq/AQx/gD6lim1punTLdoot
6ZalKY2hNKokIoGSP7x4E0946PRgjusX5U5dIc5E5OjOWetjxzjJOzAXYEvsHWCn
jzrFnRV3OD9ASHC3RgMan2W3DdlwdL9sQ6RgNf+d9HnnRMOk+fNWgw==
=S3fq
-----END PGP SIGNATURE-----

It's quite possible for anybody to go find out from this file the ID
of the key used to sign this, grab it off a key server, find out who
signed IDs on that key, and, with any luck, eventually see who's on
the verification chain between him and me, and decide how much he
trusts each of these people. With some real luck there's multiple paths
between the two people involved to increase the chances that this can be
trusted.

There are a couple of issues with this, of course.

First, the tools to do this are not so hot; there's no easy way (that
I know of) to pop this into a program, combine it with who and what
you know, and get output that will give you some sense of how much you
should trust this certificate.

Second, the whole process of how this trust chain works is not well
documented, and even were it so, it's complex enough that it probably
requires more thought than your average Joe, who will even let a waiter
in a restaurant walk off somewhere unseen with his credit card.

cjs
-- 
Curt Sampson            <[email protected]>             +81 90 7737 2974
   The power of accurate observation is commonly called cynicism
   by those who have not got it.    --George Bernard Shaw
_______________________________________________
Pine-info mailing list
[email protected]
http://mailman1.u.washington.edu/mailman/listinfo/pine-info
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.