Re: [cryptography] someone should make openssh keys expire

2013-04-09 Thread ianG
On 9/04/13 03:48 AM, travis+ml-rbcryptogra...@subspacefield.org wrote: Just saying... They have signatures now, but there's no way to effectively audit them or expire them. The question is, why? If you can answer that effectively, then you might be right. Let me put these stumbling

Re: [cryptography] someone should make openssh keys expire

2013-04-09 Thread Ralph Holz
Hi, On 04/09/2013 04:05 AM, Tom Ritter wrote: Somebody did ;) http://www.sshark.org/ Could I shamelessly self-advertise our notary service for SSH host keys? ralph@firenze:~$ dig -t TXT 131.159.15.12.cbssh.net.in.tum.de ;; ANSWER SECTION: 131.159.15.12.cbssh.net.in.tum.de. 21600 IN TXT {ip:

Re: [cryptography] ICIJ's project - comment on cryptography tools

2013-04-09 Thread Kevin W. Wall
Some OT comments to an OT response... On Mon, Apr 8, 2013 at 8:30 AM, ianG i...@iang.org wrote: On 7/04/13 09:38 AM, Nico Williams wrote: [big snip] We've built a house of cards, not so much on the Internet as on the web (but not only!). Web application security is complete mess. And