Re: getross - email privacy /security of system

Ross <[email protected]>
Newsgroups gmane.mail.pine.general
Message-ID <Pine.WNT.4.61.0611082010590.-1579513@computer101>
On Wed, 8 Nov 2006, Curt Sampson wrote:
> On Tue, 7 Nov 2006, Ross wrote:
>> Would we be better protected if we established a network where 
>> certificate authority resides in our knowledge of each other, issued as

> You have just exactly described the PGP public key infrastructure.

Yes, & I suspect relying on each other can be no worse than 
some costly certificate authority that rips off credit cards.

>> Essentially a public system not only for public PGP keys, but any
>> verification.

> That's easy enough to do with PGP as it stands. Here's an arbitrary
> "certificate" signed by me:

And you provided a good demonstration. With added signatures 
for verification, it would fly. The more signed on to a key 
ring, the better the verification of the security of the key. 
It certifies itself really.

> First, the tools to do this are not so hot; there's no easy way (that
> I know of) to pop this into a program, combine it with who and what
> you know, and get output that will give you some sense of how much you
> should trust this certificate.

You said "easy enough" & now you say "not so hot". Negative 
vibes man. The tools & quality to encrypt were what before 
Zimmerman created PGP?  Maybe not today, but the foundation 
idea must be hatched first. Then build on it. A transparent 
program should be possible. The solution may already be there 
for Pine & PGP through filters, unless U of Washington can 
provide a smoother interface for PGP type software.

The keeping of public certificates/keys for verification, 
should be the biggest problem. Only a decentralized system 
could work. Centralization works like the Soviet Union.

It would be useful if all email service providers were 
willing, & could be trusted. They are numerous enough, to 
provide secure keeping that can cross check certificates/keys, 
each other, & update with others of the same. To prevent 
tampering & any scam. Not public enough huh?

Many copies could be reconciled & would prevent a scam. I 
observe certificate authorities holding one copy does not 
work all the time.

Maybe each of us needs a webpage, part of a webpage key ring 
distribution system to solve the distribution & checking 
routine. If the webpage key ring can provide verfication of 
the same certificate/key, it is approved. The webpages cross 
check each others copy. Odd key rings a bell to all - warning!

> Second, the whole process of how this trust chain works is not well
> documented, and even were it so, it's complex enough that it probably
> requires more thought than your average Joe, who will even let a waiter
> in a restaurant walk off somewhere unseen with his credit card.

Restaurant waiter or providing the credit card number for an 
online purchase or telefone call order is about the same 
thing, buyer beware. Credit cards are a take payment system - 
ripe for abuse.

Documentation can be produced easy enough once the system is 
established. Complexity can be eliminated by building a 
transparent design. Just type the message you want to send, 
press control-x(in Pine), select Y/N to encrypt, enter 
encryption required passphrase/key, & enter to finish. All 
done. Software does the rest to verify, using public 
certificates on a webpage key ring. Receiving messages the 
same. Financial very similar, yet sellers must be involved 
with the webpage key ring, & may be one of the best members 
signed on. Bumbs & thieves could be identified quicker than 
now as well. Networks of People work!

Verification for email may be improved by the email service 
provider. I am not sure the best way to include them other 
than in the webpage key ring.

>  The power of accurate observation is commonly called cynicism
>  by those who have not got it.    --George Bernard Shaw

You provided the best quote that says it all. No negative 
vibes man - think positive.

--
RossARR
---end-of-message---
_______________________________________________
Pine-info mailing list
[email protected]
http://mailman1.u.washington.edu/mailman/listinfo/pine-info
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.