Justin Clift wrote: > certificates.services.openoffice.org perhaps? > > Maybe some kind of centralised OOo certification co-ordination authority > even. :)
This points to another problem about certs. Consider a public cert, like web.de. How does the cert know that you are really Justin Clift? Have they met Justin? Do they know his voice? Can they ask him the name of his best friend in elementary school and verify that he answered correctly? Of course not. Then how is this kind of public cert a valid form of authenticity? All it seems to do is provide a false sense of security, which can be dangerous. The only certs that seem to be reliable are those run by a company, about their employees. They can ask the employee to walk down to the cert department with a picture ID. So they are more reliable. But company certs have a whole other problem. They put certification even further beyond the reach of a regular user. This is another reason why GPG seems better to me. Who certifies the authenticity of a GPG key? Well you do. Or someone you trust. For example, I met Jean in San Diego, we could exchange keys there. Jean then met Justin in Camberra, so they exchanged keys too. Justin and I trust Jean, and through her, we obtain each other's keys. Now all three of us can communicate with confidence. > >Just an idea. What do you think? > > An interesting idea, definitely worth discussing. :-) Cheers, -- Daniel Carrera | I don't want it perfect, Join OOoAuthors today! | I want it Tuesday. http://oooauthors.org | --------------------------------------------------------------------- To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED]
