[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Authentication at toad.com: WTF?




Does the idea of having the list software check signatures strike
anybody else as a Bad Idea?  Signatures should be checked locally
by the recipient -- otherwise one might as well ask the sender to
include a statement stating whether or not a message is authentic
and should be believed.  I wouldn't want to see cypherpunks being
used to propogate this false security -- majordomo can no more be
trusted, as an external agent, than a message's sender.