-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Om 8:07 op vrijdag 18 januari 2002, Gary Mort:

> I wouldn't classify a PGP signature as secure communications.

I agree, and if that's what you think I implied, I apologize. When writing
that last paragraph, I had SSH2 in mind.

>A PGP signature just verifies that the same person wrote a series of
>messages. As such, it requires no more 'trust' on my part to beleive a
>key server download as to beleive you handing me a disk with the key on
>it. In either case, that key could be being used by you, or by someone
>else you have given it to.

Well, to paraphrase someone; "the buck has to stop somewhere". I can also
IRL forge signatures. I can also fake my ID. The 'atom' in the web of
trust is a 'person'. If you can't trust a 'person', it stops right then
and there.

The bottom line is: you have to trust *someone*. There exists no (secure)
communication for the truly truly paranoid. There is a line you have to
draw somewhere and say: "This Key I Trust".

This is the major problem with building a web of trust. If I know your
voice, you can confirm your public key by reading a bunch of words to me.
But to a complete stranger, this is rather a problem. I can give you my
phone number, but since you don't know my voice, well, no help there.

Personally, I don't really trust keys from key-servers very much. Too much
tampering possible. However, it is an useful way to transfer keys from
friends or collegues you *validate later on*.

> Its merely a convenient way of 'proving' what you did and did not say.
> And by 'you' I don't mean a person, simply an email address that is
> used repeatedly where all messages are signed with PGP.

Which still doesn't imply that the particular email-address belongs to me,
indeed... It could also be an elaborate Man In The Middle attack. I have
no way of knowing that the PGP-key you see in the messages you receive
from me are the same as the ones I send away.

> Secure communication would entail the encryption of your message
> itself, not the mere signing of it.

It still wouldn't be secure if we didn't exchange keys securely. Nor would
it be if you didn't trust me to keep the password to my private key-ring
in a safe place. Nor would it be if you didn't trust me at all :)

Mrten.

-----BEGIN PGP SIGNATURE-----
Version: PGP 6.5i

iQA/AwUBPEftGUtQMadp+KslEQJ3CgCg1AC/zRs8K9kY4ma6Glt+/m3pCWMAoLG7
CZnNj0vsDxd4bIIYF60VKxbO
=zvo1
-----END PGP SIGNATURE-----


-- 
________________________________________________________
Archives   : http://tbudl.thebat.dutaint.com
Moderators : mailto:[EMAIL PROTECTED]
TBTech List: mailto:[EMAIL PROTECTED]
Unsubscribe: mailto:[EMAIL PROTECTED]
Latest Vers: 1.53d
FAQ        : http://faq.thebat.dutaint.com 

Reply via email to