[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Proxy/Representation?



"David E. Smith" writes:
>That's more of what I was looking for.  I suppose that (I'm still using
>PGP as my example) there could be a shared PGP key, signed by Helen and
>myself, where only the two of us know the passphrase, with a keyid of
>"David Smith <[email protected]> on behalf of Helen Jones <[email protected]>"
>or something similar.  The obvious problem is that in sharing the pass
>phrase the security is weakened.  (Paranoid threat model: at some point
>we have to decide on the pass phrase, and we are videotaped/bugged/spied
>upon while this takes place.)

Why bother with the shared key?  You need a message from Helen describing
the powers with which you are invested, signed by her key.  The wonderful
thing about data is that copying it is virtually free.  When you issue an 
order on her behalf, include a copy of the signed PoA, and sign the whole
thing with your key.