[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]
On 28 Apr, 2013, at 12:52 pm, Martijn Grooten wrote:
What is a much bigger problem is authentication. If I send an email that only you can decrypt, how do I know that the 'you' is the 'you' the email is intended for? And if I send such an email signed in a way that only I could have signed, how do you know that the 'I' is the 'I' you think it is?
Just to be clear, Martijn knows the current best answer to this; he's asking to get those who don't to think about it (I assume).
That answer BTW is "the web of trust".I wish this stuff was less complicated, but ATM it seems like public key cryptography + web of trust *is* the simplest possible solution. Unfortunately that limits it to the cross section of the upper quartile of the IQ range, people with access to learning about it, people with the time to learn it, people with the inclination to learn it, people who (see that they) have a need for it, and people with usable tools. To a first approximation, the population of that set is zero. Damn damn damn.
-- Phil Hudson http://hudson-it.no-ip.biz @UWascalWabbit PGP/GnuPG ID: 0x887DCA63 -- The Mailing List for the Devon & Cornwall LUG http://mailman.dclug.org.uk/listinfo/list FAQ: http://www.dcglug.org.uk/listfaq