-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Om 8:07 op vrijdag 18 januari 2002, Gary Mort:
> I wouldn't classify a PGP signature as secure communications. I agree, and if that's what you think I implied, I apologize. When writing that last paragraph, I had SSH2 in mind. >A PGP signature just verifies that the same person wrote a series of >messages. As such, it requires no more 'trust' on my part to beleive a >key server download as to beleive you handing me a disk with the key on >it. In either case, that key could be being used by you, or by someone >else you have given it to. Well, to paraphrase someone; "the buck has to stop somewhere". I can also IRL forge signatures. I can also fake my ID. The 'atom' in the web of trust is a 'person'. If you can't trust a 'person', it stops right then and there. The bottom line is: you have to trust *someone*. There exists no (secure) communication for the truly truly paranoid. There is a line you have to draw somewhere and say: "This Key I Trust". This is the major problem with building a web of trust. If I know your voice, you can confirm your public key by reading a bunch of words to me. But to a complete stranger, this is rather a problem. I can give you my phone number, but since you don't know my voice, well, no help there. Personally, I don't really trust keys from key-servers very much. Too much tampering possible. However, it is an useful way to transfer keys from friends or collegues you *validate later on*. > Its merely a convenient way of 'proving' what you did and did not say. > And by 'you' I don't mean a person, simply an email address that is > used repeatedly where all messages are signed with PGP. Which still doesn't imply that the particular email-address belongs to me, indeed... It could also be an elaborate Man In The Middle attack. I have no way of knowing that the PGP-key you see in the messages you receive from me are the same as the ones I send away. > Secure communication would entail the encryption of your message > itself, not the mere signing of it. It still wouldn't be secure if we didn't exchange keys securely. Nor would it be if you didn't trust me to keep the password to my private key-ring in a safe place. Nor would it be if you didn't trust me at all :) Mrten. -----BEGIN PGP SIGNATURE----- Version: PGP 6.5i iQA/AwUBPEftGUtQMadp+KslEQJ3CgCg1AC/zRs8K9kY4ma6Glt+/m3pCWMAoLG7 CZnNj0vsDxd4bIIYF60VKxbO =zvo1 -----END PGP SIGNATURE----- -- ________________________________________________________ Archives : http://tbudl.thebat.dutaint.com Moderators : mailto:[EMAIL PROTECTED] TBTech List: mailto:[EMAIL PROTECTED] Unsubscribe: mailto:[EMAIL PROTECTED] Latest Vers: 1.53d FAQ : http://faq.thebat.dutaint.com

