Re: getross - email privacy /security of system
Ross <[email protected]>
| Newsgroups | gmane.mail.pine.general |
|---|---|
| Message-ID | <Pine.WNT.4.61.0611082010590.-1579513@computer101> |
On Wed, 8 Nov 2006, Curt Sampson wrote: > On Tue, 7 Nov 2006, Ross wrote: >> Would we be better protected if we established a network where >> certificate authority resides in our knowledge of each other, issued as > You have just exactly described the PGP public key infrastructure. Yes, & I suspect relying on each other can be no worse than some costly certificate authority that rips off credit cards. >> Essentially a public system not only for public PGP keys, but any >> verification. > That's easy enough to do with PGP as it stands. Here's an arbitrary > "certificate" signed by me: And you provided a good demonstration. With added signatures for verification, it would fly. The more signed on to a key ring, the better the verification of the security of the key. It certifies itself really. > First, the tools to do this are not so hot; there's no easy way (that > I know of) to pop this into a program, combine it with who and what > you know, and get output that will give you some sense of how much you > should trust this certificate. You said "easy enough" & now you say "not so hot". Negative vibes man. The tools & quality to encrypt were what before Zimmerman created PGP? Maybe not today, but the foundation idea must be hatched first. Then build on it. A transparent program should be possible. The solution may already be there for Pine & PGP through filters, unless U of Washington can provide a smoother interface for PGP type software. The keeping of public certificates/keys for verification, should be the biggest problem. Only a decentralized system could work. Centralization works like the Soviet Union. It would be useful if all email service providers were willing, & could be trusted. They are numerous enough, to provide secure keeping that can cross check certificates/keys, each other, & update with others of the same. To prevent tampering & any scam. Not public enough huh? Many copies could be reconciled & would prevent a scam. I observe certificate authorities holding one copy does not work all the time. Maybe each of us needs a webpage, part of a webpage key ring distribution system to solve the distribution & checking routine. If the webpage key ring can provide verfication of the same certificate/key, it is approved. The webpages cross check each others copy. Odd key rings a bell to all - warning! > Second, the whole process of how this trust chain works is not well > documented, and even were it so, it's complex enough that it probably > requires more thought than your average Joe, who will even let a waiter > in a restaurant walk off somewhere unseen with his credit card. Restaurant waiter or providing the credit card number for an online purchase or telefone call order is about the same thing, buyer beware. Credit cards are a take payment system - ripe for abuse. Documentation can be produced easy enough once the system is established. Complexity can be eliminated by building a transparent design. Just type the message you want to send, press control-x(in Pine), select Y/N to encrypt, enter encryption required passphrase/key, & enter to finish. All done. Software does the rest to verify, using public certificates on a webpage key ring. Receiving messages the same. Financial very similar, yet sellers must be involved with the webpage key ring, & may be one of the best members signed on. Bumbs & thieves could be identified quicker than now as well. Networks of People work! Verification for email may be improved by the email service provider. I am not sure the best way to include them other than in the webpage key ring. > The power of accurate observation is commonly called cynicism > by those who have not got it. --George Bernard Shaw You provided the best quote that says it all. No negative vibes man - think positive. -- RossARR ---end-of-message--- _______________________________________________ Pine-info mailing list [email protected] http://mailman1.u.washington.edu/mailman/listinfo/pine-info