Re: Verisign and MITM

> An interesting "direct demonstration" of this would be to get a certificate
> generated for a well-known company, institution, or political candidate.
> This would demonstrate the flaws in the e-mai/fax/snailmail process like
> nothing else.

	That wasn't quite the point. If I submitted a key and
paperwork for the key claiming to be Jim Bidzos, and they gave me a
cert for that, that wasn't my point. My point was simply the technical
linking of the paperwork and the key. I figured that a relatively easy
way to fix that would be to require an MD5 of the key included with
the faxed paperwork. It has been mentioned to me though that an MITM
would be noticed once verisign sent me back a signed cert and it
didn't work with my key.

