Peter Maxwell <[email protected]> writes:

>Why on earth would you need to spread your private-key across any number of
>less secure machines?

The technical details are long and tedious (a pile of machines that need to
talk via SSH because telnet and FTP were turned off/firewalled years ago, I
won't bore you with the details).  The important point isn't the technical
details but the magical thinking, "a private key sprayed all over the place in
plaintext is more secure than a line-noise password because everyone knows
passwords are insecure and PKCs are secure" (and, as I've said, this isn't an
isolated case).

Peter.
_______________________________________________
cryptography mailing list
[email protected]
http://lists.randombit.net/mailman/listinfo/cryptography

Reply via email to