On 8 Dec 2008, at 22:43, David G. Koontz wrote:

JOHN GALT wrote:
StealthMonger wrote:

This may help to explain the poor uptake of encrypted email. It would
be useful to know exactly what has been discovered.  Can you provide

The iconic Paper explaining this is "Why Johnny Can't Encrypt" available
here:  http://portal.acm.org/citation.cfm?id=1251435

Available from the Authors:


A later follow up (s/mime; more focus on the KDC):


is IMHO more interesting - as it explores a more realistic hostile scenario, seems to pinpoint the core security issue better; and goes to some length to evaluate remedial steps. And it does show that a large swath of issues in PGP are indeed solvable/solved (now)



