Re: reflecting on PGP, keyservers, and the Web of Trust

2000-09-06 Thread Ted Lemon
If you sign the revocation certificate in the compromised key, then the only way it can get revoked is if the owner of the key revokes it or it's been compromised... _MelloN_

Re: reflecting on PGP, keyservers, and the Web of Trust

2000-09-06 Thread Ben Laurie
Ray Dillinger wrote: On Tue, 5 Sep 2000, David Honig wrote: The more hard-core distribute keys to previously known parties on physical media, only. I have long felt that PGP missed a trick when it didn't have automatic expiry for keys -- It should be possible to build into each

Re: Secrets Lies, a comment (proactive security)

2000-09-06 Thread amir . herzberg
Ed replied to me, [EMAIL PROTECTED] wrote: Ed says, The solution is to use a multifold of links, arranged in time and space such that rather than making the impossible assumption that "no part will fail at any time," we can design a system where up to M parts can fail at any

US stole Codebreaking Limelight from Britain in WWII?

2000-09-06 Thread Peter Wayner
According to the Daily Telegraph, the US took most of the credit for breaking Japanese codes during WWII. The paper says that Bletchley Park deserves more credit according to recently declassified papers. Only traditional British reticence kept them from claiming credit before.

Re: reflecting on PGP, keyservers, and the Web of Trust

2000-09-06 Thread Paul Crowley
I'm still far from convinced that the Web of Trust achieves what it's supposed to achieve, even when used correctly. Consider this question: what do you need to know about a person in order to feel confident that they are the intended recipient of your secure communication? Because I bet the

RSA Patent gone two weeks early

2000-09-06 Thread Perry E. Metzger
RSA Security has released the RSA patent into the public domain two weeks early, apparently in a successful attempt to generate publicity. http://www.rsasecurity.com/news/pr/000906-1.html They're also giving away neat RSA algorithm T-Shirts and have a FAQ about the patent expiry.

Re: Secrets Lies, a comment

2000-09-06 Thread Jaap-Henk Hoepman
On Fri, 1 Sep 2000 15:06:52 +0300 [EMAIL PROTECTED] writes: Ed says, The solution is to use a multifold of links, arranged in time and space such that rather than making the impossible assumption that "no part will fail at any time," we can design a system where up to M parts can fail

Re: reflecting on PGP, keyservers, and the Web of Trust

2000-09-06 Thread Ray Dillinger
On Tue, 5 Sep 2000, Ted Lemon wrote: If you sign the revocation certificate in the compromised key, then the only way it can get revoked is if the owner of the key revokes it or it's been compromised... _MelloN_ This is true, and that's a *sufficient* condition

Re: reflecting on PGP, keyservers, and the Web of Trust

2000-09-06 Thread David Honig
At 10:47 PM 9/5/00 -0400, Dan Geer wrote: I can tell people never to accept an executable mailed to them from anywhere, which will get laughed at by all the people in the business world who... [...who are digging their own graves if they routinely run programs mailed to them, whether or not

RE: US stole Codebreaking Limelight from Britain in WWII?

2000-09-06 Thread Kossmann, Bill
Peter Wayner wrote: According to the Daily Telegraph, the US took most of the credit for breaking Japanese codes during WWII. snip If I recall correctly, the Americans were successful in breaking the Japanese diplomatic cipher 'Purple'. This gave them some indication that something was up in

Five big schools nix Carnivore review

2000-09-06 Thread rodger
Researchers refuse Carnivore review By Will Rodger, USATODAY.com Five groups of researchers have bowed out of the competition to evaluate the so-called Carnivore Internet surveillance system. And that likely will dash Justice Department hopes that a major university would validate its

Re: reflecting on PGP, keyservers, and the Web of Trust

2000-09-06 Thread Derek Atkins
RFC2440 (OpenPGP) provides for referral revocations -- you can let other people revoke your key on your behalf. -derek Ray Dillinger [EMAIL PROTECTED] writes: On Tue, 5 Sep 2000, Ted Lemon wrote: If you sign the revocation certificate in the compromised key, then the only way it can get

Re: reflecting on PGP, keyservers, and the Web of Trust

2000-09-06 Thread Derek Atkins
Ray Dillinger [EMAIL PROTECTED] writes: I have long felt that PGP missed a trick when it didn't have automatic expiry for keys -- It should be possible to build into each key an expiration date, fixed at the time of its creation. For shorter keys, it ought to default to expiring

DCSB: RSA Expiration Fundraiser for EFF, Downtown Harvard Club ofBoston

2000-09-06 Thread R. A. Hettinga
-BEGIN PGP SIGNED MESSAGE- The Members of The Digital Commerce Society of Boston, Rent this Space* :-), and The Internet Bearer Underwriting Corporation In Celebration of the

Re: RSA Security releases RSA algoritm into public domain two weeks early. [cpunk]

2000-09-06 Thread Eric Murray
On Wed, Sep 06, 2000 at 09:36:32AM -0700, Bill Stewart wrote: When will we see the first RSAREF-compatible public-domain code? 'BSAFEeay', a BSAFE API layer on top of SSLeay's crypto lib, was put up on the net about three years ago. It was mostly complete. I beleive that RSAREF is the same

Re: DeCSS and first sale

2000-09-06 Thread John R Levine
[ I was at the beach, catching up now ] It is a test of will and power. Kaplan took offense at the widespread attitude that such an act was beyond the power of a judge, that judges not only should not censor thei internet, but that they *could* not censor the internet, that the

Re: reflecting on PGP, keyservers, and the Web of Trust

2000-09-06 Thread Arnold G. Reinhold
At 4:38 PM -0700 9/5/2000, David Honig wrote: At 05:33 PM 9/3/00 -0400, Dan Geer wrote: How do they exchange public keys? Via email I'll bet. Note that it is trivial(*) to construct a self-decrypting archive and mail it in the form of an attachment. The recipient will merely have to

RSA Security releases RSA algoritm into public domain two weeks early. [cpunk]

2000-09-06 Thread Trei, Peter
Wednesday September 6, 8:03 am Eastern Time Press Release SOURCE: RSA Security Inc. RSA Security Releases RSA Encryption Algorithm into Public Domain 'c = m(e) mod n' Made Available Two Weeks Early BEDFORD, Mass., Sept. 6 /PRNewswire/ -- RSA® Security Inc. (Nasdaq: RSAS - news) today