Re: Attacks against GOST? Was: Protocol Construction

2009-08-06 Thread Joseph Ashwood
My apologies for the delay, I had forgotten the draft message. -- From: Alexander Klimov alser...@inbox.ru Subject: Attacks against GOST? Was: Protocol Construction On Sun, 2 Aug 2009, Joseph Ashwood wrote: So far, evidence supports the idea

Re: Client Certificate UI for Chrome?

2009-08-06 Thread James A. Donald
Ben Laurie wrote: So, I've heard many complaints over the years about how the UI for client certificates sucks. Now's your chance to fix that problem - we're in the process of thinking about new client cert UI for Chrome, and welcome any input you might have. Obviously fully-baked proposals are

Re: Client Certificate UI for Chrome?

2009-08-06 Thread Peter Gutmann
Ben Laurie b...@google.com writes: So, I've heard many complaints over the years about how the UI for client certificates sucks. Now's your chance to fix that problem - we're in the process of thinking about new client cert UI for Chrome, and welcome any input you might have. Obviously

Re: cleversafe says: 3 Reasons Why Encryption is Overrated

2009-08-06 Thread Ben Laurie
Zooko Wilcox-O'Hearn wrote: I don't think there is any basis to the claims that Cleversafe makes that their erasure-coding (Information Dispersal)-based system is fundamentally safer, e.g. these claims from [3]: a malicious party cannot recreate data from a slice, or two, or three, no matter

Re: Client Certificate UI for Chrome?

2009-08-06 Thread Anne Lynn Wheeler
On 08/06/09 07:33, James A. Donald wrote: The fundamental problem with certificates is getting them. digital certificate design point supposedly was the dial-up email of the early 80s, dial-up, exchange email, hang-up ... and then faced with how to deal with first time email from complete

RE: Client Certificate UI for Chrome?

2009-08-06 Thread Thomas Hardjono
Ben, Having worked at a large CA for along time (trying to push for client-side certs with little luck), here are some thoughts on what Chrome could provide: (a) Association with net identities: Provide some way for the user to associate his/her X.509 cert with an internet identity string (eg.