Microsoft info-cards to use blind signatures?

2005-05-23 Thread David Wagner
http://www.idcorner.org/index.php?p=88 The Identity Corner Stephan Brands I am genuinely excited about this development, if it can be taken as an indication that Microsoft is getting serious about privacy by design for identity management. That is a big if, however: indeed, the same Microsoft

DTV Content Protection (fwd from [EMAIL PROTECTED])

2005-05-23 Thread David Wagner
Anonymous wrote: DTV Content Protection [...] Similar concepts are presented in http://apache.dataloss.nl/~fred/www.nunce.org/hdcp/hdcp111901.htm by Scott Crosby, Ian Goldberg, Robert Johnson, Dawn Song and David Wagner. This paper assumes (unlike Irwin) that attackers have access to the private

Re: What happened with the session fixation bug?

2005-05-23 Thread James A. Donald
-- James A. Donald: PKI was designed to defeat man in the middle attacks based on network sniffing, or DNS hijacking, which turned out to be less of a threat than expected. However, the session fixation bugs http://www.acros.si/papers/session_fixation.pdf make https and PKI

Plan to Let F.B.I. Track Mail in Terrorism Inquiries

2005-05-23 Thread R.A. Hettinga
http://www.nytimes.com/2005/05/21/politics/21terror.html?ei=5065en=5515a53963929748ex=1117339200partner=MYWAYpagewanted=print The New York Times May 21, 2005 Plan to Let F.B.I. Track Mail in Terrorism Inquiries By ERIC LICHTBLAU WASHINGTON, May 20 - The F.B.I. would gain broad authority to

Re: how email encryption should work (and how to get it used...)

2005-05-23 Thread James A. Donald
-- On 30 Mar 2005 at 13:00, Amir Herzberg wrote: A missing element is motivation for getting something like this deployed... I think spam could offer such motivation; and, I strongly believe that a cryptographic protocol to penalize spammers could be one of the most important tools