Re: getross - email privacy /security of system
Ross <[email protected]>
| Newsgroups | gmane.mail.pine.general |
|---|---|
| Message-ID | <Pine.WNT.4.61.0611101943080.-1702201@computer101> |
On Fri, 10 Nov 2006, Curt Sampson wrote: > On Thu, 9 Nov 2006, Ross wrote: >> And you provided a good demonstration. With added signatures for > I think you misunderstand slightly, or I'm misunderstanding you. > No 'added" signatures are necessary, unless you want a witness that > it was really me who encrypted it. That someone with the key 25808B3A > signed that document is indisputable. The only question is, do you > ... > but at the signatures on a copy of the public key, one > copy of which you can examine at You say "no added signatures are necessary" first. Yes, added signatures are required for anything serious. Then it seems you say above "signatures on a copy", more than yours? That is good. Maybe we do not understand. I want a witness, maybe many, depending on what I would be dealing with for info. I want to be sure it is you. To simplify my response without major typing, I reference PGP documentation "How to protect public keys from tampering." That explains compromise of your key. I will not be sloppy as you understand what that means, because I read that later in this message from you. > systems to implment what you wanted. By not so hot I mean we need better > interfaces into the existing system. And so better interfaces can be programmed. Again I say complexity can be eliminated by building a transparent design. A better interface. Programming may be required. > Unfortunately, the complexity cannot be eliminated. The one part you've > described is easy, but you've ignored the issues of how that person > sending the mail has managed his key and, more particularly for this one > exchange, how the receive verifies the identity of the sender. > Fact is, if people were generally good at that latter operation, we > wouldn't have phishing scams. You are not describing complexity to be eliminated, you are describing slobs, part of my argument that your key needs witnesses so I know you are not sloppy or compromised. Complexity was eliminated by the creator of PGP to create encryption, & can be eliminated further to interface with other software & final use. It is software. Sloppy key creation, management, distribution, handling, can only be eliminated by eliminating sloppy People. Slobs are slobs. The lazy, ignorant, & dangerous will always be with us. Those of that calibre would not be safe to send anything serious to anyway, & so must be cut out of any communications I think to be confidential. Even if simple, secure, closed & opened properly with proper key handling, confidential info would more than likely be compromised by slobs telling everybody at the barber shop. Do you want to send confidential messages to People like that? Security starts with a major premise, that access to certain info is provided only to those that "need to know" & are trustworthy. Mouthy People do not get confidential info from me, so who cares about how they handle their keys. The mear existence of an encrypted key does not make one trustworthy. -- RossARR ---end-of-message--- _______________________________________________ Pine-info mailing list [email protected] http://mailman1.u.washington.edu/mailman/listinfo/pine-info