Re: public key vs passwd authentication?

From: Michael Sierchio (kudzu_at_tenebras.com)
Date: 10/02/03

  • Next message: dkoleary_at_attbi.com: "Re: public key vs passwd authentication?"
    Date: Thu, 02 Oct 2003 13:02:43 -0700
    
    

    Anne & Lynn Wheeler wrote:

    > PKI certificates are there purely as a trust propogation mechanism,
    > analogous to letters of credit (from the days of sailing ships);

    No, they aren't even remotely analogous. In the case of
    a letter of credit, the issuing bank has a liability. The
    "included by reference" CPAs in most certs that are "trusted"
    (because trusted signers are embedded in your browser/MUA/etc.)
    deny any liability, etc.

    Even if we accept that due care was taken in the binding of
    a subject id to a public key, and the extensions baked into the
    cert are appropriate, what do we know about the conditions
    under which the private key is held? And conferring trust
    usually means *authorization* not *authentication*.

    Knowing that this really is *my* public key is of limited value in se.

    I'm sure you'll respond with something about attribute certs, which
    still don't form the basis of a trust management system by themselves.


  • Next message: dkoleary_at_attbi.com: "Re: public key vs passwd authentication?"

    Relevant Pages

    • Re: Cabot debt collectors
      ... I kept getting letters from Cabot debt collectors claiming ... I owe a bank (RBS) £1200+ and honestly do not recall any such ... this matter removed from my credit file? ...
      (uk.legal)
    • Re: How were "parts" paid?
      ... Thank you Paul, that's very interesting. ... they received income from several manors in this way, ... letters of credit for whatever commoditythe manor produced. ...
      (soc.history.medieval)
    • Re: Passed 70-210 today
      ... gives credit for some Comptia Certs, ... >> questions pertaining to security templates and NTFS ... does Microsoftgive credit for Cisco ...
      (microsoft.public.cert.exam.mcse)
    • Re: What books would you recommend to would-be hard SF authors? (was Re: The moment the willing
      ... In our history, letters of credit ... > But this just pushes back the question; where are those assets and who's ... > food-producing economy but seems blissfully ignorant of anything beyond Bree. ...
      (rec.arts.sf.written)
    • OT: o.k., heres something to rile nearly everybody
      ... TODAY'S TWO MINUTES HATE....Here's the latest reason to hate credit card ... repayment history with American Express.” Here's what they told the Atlanta ... “The letters were wrong to imply we were looking at specific ...
      (rec.food.cooking)