Re: getross - email privacy /security of system

Ross <[email protected]>
Newsgroups gmane.mail.pine.general
Message-ID <Pine.WNT.4.61.0611101943080.-1702201@computer101>
On Fri, 10 Nov 2006, Curt Sampson wrote:
> On Thu, 9 Nov 2006, Ross wrote:
>> And you provided a good demonstration. With added signatures for

> I think you misunderstand slightly, or I'm misunderstanding you.
> No 'added" signatures are necessary, unless you want a witness that
> it was really me who encrypted it. That someone with the key 25808B3A
> signed that document is indisputable. The only question is, do you
> ...
> but at the signatures on a copy of the public key, one 
> copy of which you can examine at

You say "no added signatures are necessary" first. Yes, added 
signatures are required for anything serious. Then it seems 
you say above "signatures on a copy", more than yours?  That 
is good. Maybe we do not understand.

I want a witness, maybe many, depending on what I would be 
dealing with for info. I want to be sure it is you. To 
simplify my response without major typing, I reference PGP 
documentation "How to protect public keys from tampering." 
That explains compromise of your key. I will not be sloppy as 
you understand what that means, because I read that later in 
this message from you.

> systems to implment what you wanted. By not so hot I mean we need better
> interfaces into the existing system.

And so better interfaces can be programmed. Again I say 
complexity can be eliminated by building a transparent 
design. A better interface. Programming may be required.

> Unfortunately, the complexity cannot be eliminated. The one part you've
> described is easy, but you've ignored the issues of how that person
> sending the mail has managed his key and, more particularly for this one
> exchange, how the receive verifies the identity of the sender.
> Fact is, if people were generally good at that latter operation, we
> wouldn't have phishing scams.

You are not describing complexity to be eliminated, you are 
describing slobs, part of my argument that your key needs 
witnesses so I know you are not sloppy or compromised. 
Complexity was eliminated by the creator of PGP to create 
encryption, & can be eliminated further to interface with 
other software & final use. It is software.

Sloppy key creation, management, distribution, handling, can 
only be eliminated by eliminating sloppy People. Slobs are 
slobs. The lazy, ignorant, & dangerous will always be with us. 
Those of that calibre would not be safe to send anything 
serious to anyway, & so must be cut out of any communications 
I think to be confidential.

Even if simple, secure, closed & opened properly with proper 
key handling, confidential info would more than likely be 
compromised by slobs telling everybody at the barber shop. Do 
you want to send confidential messages to People like that?

Security starts with a major premise, that access to certain 
info is provided only to those that "need to know" & are 
trustworthy. Mouthy People do not get confidential info from 
me, so who cares about how they handle their keys. The mear 
existence of an encrypted key does not make one trustworthy.

--
RossARR
---end-of-message---
_______________________________________________
Pine-info mailing list
[email protected]
http://mailman1.u.washington.edu/mailman/listinfo/pine-info
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.