[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Certificate proposal




Adam Shostack writes:
 > 	If a MITM attack would be useful, then there will be times
 > when one will be mounted.  It might take 30 law enforcement officers
 > to do it, but it has been demonstrated that the FBI will use that many
 > people for a year or more on some cases.  The CIA and NSA can be
 > presumed to be willing to spend more time and effort to get certain
 > results.

Right; if there's that much energy being expended, then I have no
reason to trust that just because the Department of Keys tells me that
a particular key belongs to one "Alice B. Crypto" it's really the same
Alice I think I know.  I'll make sure that we verify our keys in
person.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
| Nobody's going to listen to you if you just | Mike McNally ([email protected]) |
| stand there and flap your arms like a fish. | Tivoli Systems, Austin TX    |
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~