On Tue, 2008-05-13 at 16:32 -0400, Bill Michaelson wrote: > Referring back to my earlier suggestion about public key > authentication, a more widespread appreciation and understanding of > it's applicability in various realms would go a long way toward > helping solve many problems ranging from spam and phishing to stuff > like this. It's a mind-share/social problem. There is nothing > inherently wrong with spoofing; the problems arise when the receiver > is unduly deceived.
that only works if you can trust the key holders. Someone has to have your public key and be trusted so that you know its real, and not a fake one. Yes you can cache it once you have had contact but not first contact. Further when you get phone calls that are authenticated on each end as to whom you are talking there will be abuses. It will be used as a method of surveilance and tracking by governments, presumably it will be a smart card type device and not the phone itself, and when you go from phone to phone you will ultimately be required to insert it to prove identity. After all this will help stop drug dealers, child pornographers and terrorists right? (those are the 3 claims that most of the tracking laws have used for the last 15-20 years). But it wont stop there, this can help stop credit card theft on the intarweb, so it will be mandated that you use it there too, meaning you wont be able to do anything online anonymous, because you will have to authenticate with your card. Why stop there, make it some type of RFID system so that they can monitor who you are as you drive down the road (michelin has a plan to put RFIDs in tires and claim they can be read upto 90mph so its not just a random theory). While you arent proposing all of this, think for a second about how many governments have been clamoring for something like this. End to end authentication is not always a good thing, it may be helpful in a couple of situations but at what cost? -- Trixter http://www.0xdecafbad.com Bret McDanel Belfast +44 28 9099 6461 US +1 516 687 5200 http://www.trxtel.com the phone company that pays you! _______________________________________________ --Bandwidth and Colocation Provided by http://www.api-digital.com-- asterisk-biz mailing list To UNSUBSCRIBE or update options visit: http://lists.digium.com/mailman/listinfo/asterisk-biz
