Re: getross - email privacy /security of system
Curt Sampson <[email protected]>
| Newsgroups | gmane.mail.pine.general |
|---|---|
| Message-ID | <Pine.NEB.4.64.0611080916310.6451@localhost> |
On Tue, 7 Nov 2006, Ross wrote: > I do not know any of you. Yet I do know People that know me, as do you. Would > we be better protected if we established a network where certificate > authority resides in our knowledge of each other, issued as public > certificates? A slow building system that can be controlled outside > establishments? You have just exactly described the PGP public key infrastructure. > Essentially a public system not only for public PGP keys, but any > verification. That's easy enough to do with PGP as it stands. Here's an arbitrary "certificate" signed by me: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 THIS IS A SAMPLE THIS IS A SAMPLE THIS IS A SAMPLE I assert that I have received on 2006-11-07 from Joe Bloggs <[email protected]> the sum of USD 0.03, which I have agreed to return in full by 2007-03-01. (This is a sample of a "certificate" created and signed by "me". See the key information to find out who "I" am. This text file could be any sort of contract.) THIS IS A SAMPLE THIS IS A SAMPLE THIS IS A SAMPLE -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.5 (NetBSD) iQEVAwUBRVEjwagqOkIlgIs6AQLOLggA1nRhuXCLXKmyM9c1LLGfTxzShUuvxy18 d/iu7mXoG2qqFc+f/WMcXeEOZ8kF2t1911ixcE5AXRbToryi6yVO8w1x3Y1tHlWe bkPa0EwkJ6XNLKQ7OAZrLbn7M4Z+vXY+s9bj9maN37x4sKdGkPVdYIOF8AkNCj2p dL9jSjDQbnSnkr5ifav/sJWeSOH7IifVKrxfsCXn3jq/AQx/gD6lim1punTLdoot 6ZalKY2hNKokIoGSP7x4E0946PRgjusX5U5dIc5E5OjOWetjxzjJOzAXYEvsHWCn jzrFnRV3OD9ASHC3RgMan2W3DdlwdL9sQ6RgNf+d9HnnRMOk+fNWgw== =S3fq -----END PGP SIGNATURE----- It's quite possible for anybody to go find out from this file the ID of the key used to sign this, grab it off a key server, find out who signed IDs on that key, and, with any luck, eventually see who's on the verification chain between him and me, and decide how much he trusts each of these people. With some real luck there's multiple paths between the two people involved to increase the chances that this can be trusted. There are a couple of issues with this, of course. First, the tools to do this are not so hot; there's no easy way (that I know of) to pop this into a program, combine it with who and what you know, and get output that will give you some sense of how much you should trust this certificate. Second, the whole process of how this trust chain works is not well documented, and even were it so, it's complex enough that it probably requires more thought than your average Joe, who will even let a waiter in a restaurant walk off somewhere unseen with his credit card. cjs -- Curt Sampson <[email protected]> +81 90 7737 2974 The power of accurate observation is commonly called cynicism by those who have not got it. --George Bernard Shaw _______________________________________________ Pine-info mailing list [email protected] http://mailman1.u.washington.edu/mailman/listinfo/pine-info