[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Authentication at toad.com: WTF?
Does the idea of having the list software check signatures strike
anybody else as a Bad Idea? Signatures should be checked locally
by the recipient -- otherwise one might as well ask the sender to
include a statement stating whether or not a message is authentic
and should be believed. I wouldn't want to see cypherpunks being
used to propogate this false security -- majordomo can no more be
trusted, as an external agent, than a message's sender.