[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Certificate proposal
Adam Shostack writes:
> If a MITM attack would be useful, then there will be times
> when one will be mounted. It might take 30 law enforcement officers
> to do it, but it has been demonstrated that the FBI will use that many
> people for a year or more on some cases. The CIA and NSA can be
> presumed to be willing to spend more time and effort to get certain
> results.
Right; if there's that much energy being expended, then I have no
reason to trust that just because the Department of Keys tells me that
a particular key belongs to one "Alice B. Crypto" it's really the same
Alice I think I know. I'll make sure that we verify our keys in
person.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
| Nobody's going to listen to you if you just | Mike McNally ([email protected]) |
| stand there and flap your arms like a fish. | Tivoli Systems, Austin TX |
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~