Failure of PKI in messaging

2007-02-12 Thread James A. Donald
-- Obviously financial institutions should sign their messages to their customers, to prevent phishing. The only such signatures I have ever seen use gpg and come from niche players. I have heard that the reason no one signs using PKI is that lots of email clients throw up panic dialogs

Re: Failure of PKI in messaging

2007-02-12 Thread Matt Blaze
I'm all for email encryption and signatures, but I don't see how this would help against today's phishing attacks very much, at least not without a much better trust management interface on email clients (of a kind much better than currently exists in web browsers). Otherwise the phishers could

Re: Failure of PKI in messaging

2007-02-12 Thread Steven M. Bellovin
On Mon, 12 Feb 2007 17:03:32 -0500 Matt Blaze [EMAIL PROTECTED] wrote: I'm all for email encryption and signatures, but I don't see how this would help against today's phishing attacks very much, at least not without a much better trust management interface on email clients (of a kind much