1995-10-11 - Re: Man in the Middle Revisited (but not for the last time)

Header Data

From: Bryce <wilcoxb@nagina.cs.colorado.edu>
To: tcmay@got.net (Timothy C. May)
Message Hash: 60f4cf235f87d762f2651e892fad1bb2f9003d9c2c9432a69fcac32e9f8c63e9
Message ID: <199510110337.VAA20392@nagina.cs.colorado.edu>
Reply To: <ac9ec6b5070210049d4b@[205.199.118.202]>
UTC Datetime: 1995-10-11 03:37:30 UTC
Raw Date: Tue, 10 Oct 95 20:37:30 PDT

Raw message

From: Bryce <wilcoxb@nagina.cs.colorado.edu>
Date: Tue, 10 Oct 95 20:37:30 PDT
To: tcmay@got.net (Timothy C. May)
Subject: Re: Man in the Middle Revisited (but not for the last time)
In-Reply-To: <ac9ec6b5070210049d4b@[205.199.118.202]>
Message-ID: <199510110337.VAA20392@nagina.cs.colorado.edu>
MIME-Version: 1.0
Content-Type: text/plain



-----BEGIN PGP SIGNED MESSAGE-----

 The entity calling itself "Timothy C. May" <tcmay@got.net> is alleged to
 have written:
>
> I don't know if "Carl Ellison the Key" is "really" the same Carl Ellison
> that Carl Ellison the Key claims to be...you see the semantic difficulties.

<snip>


Ah, but what we are concerned with is whether "Carl Ellison the Key" is
*really* the same "Carl Ellison the Key" that you think he is.  :-)  Or
to put it another way, that *he* thinks he is the same "C.E. the Key" 
that you think he is.


> To put it bluntly, all I really care about is _persistent_ key-holding,
> i.e., that the person who began posting with a given key is still using the
> same key. Or, rather, I don't even care if the keyholder "Pr0duct Cypher"
> is actually a person, or a Bourbaki-style committee--I only care that
> messages purporting to be from Pr0duct Cypher or Black Unicorn or Carl
> Ellison are still using the same key.
> 
> Who any of these entities "really" are is irrelevant to me. (I don't even
> know if Hal Finney, who I met once a few years ago, is the "real" Hal
> Finney, nor do I really care.)


Well and good, Tim, but you *do* care if the entity calling itself "Hal
Finney" is being surrounded by the Man in the Channel ("Mitch") and all 
of your communications with that entity are under Mitch's control.  For
example, you may choose to enter a contract with the entity calling
itself "Hal Finney", and provide some sort of consulting service to it
in exchange for 10,000 cyberbucks.  If Mitch is actually in control
then he could easily steal both the output of your consultation *and* 
Hal's 10,000 cyberbucks and leave the two of you hating each other.


Perhaps by "persistent key-holding" you mean to imply "without being
spoofed by Mitch", in which case I'm sure that you agree on the
importance of anti-Mitch measures.  :-)


Bryce

signatures follow


            "To strive, to seek, to find and not to yield."   
    <a href="http://ugrad-www.cs.colorado.edu/~wilcoxb/Niche.html">

                          bryce@colorado.edu                   </a>


-----BEGIN PGP SIGNATURE-----
Version: 2.6.2
Comment: Auto-signed under Unix with 'BAP' Easy-PGP v1.01

iQCVAwUBMHs70fWZSllhfG25AQECWwQAnk/HRTk/h0tCT80AriH28yLlCQiciGmV
T1LShDolvEGEgHThm7tG4LGRVoVUyn7h4MbmJMCXsOV7i0RlvMTA4yVZW9KIiN4O
lSzWIQSdIYLS2SQ93cmDART6kV0BBC50FeAAfEBy9PNPaX7ifjmpB0QFzjeLxTG5
TXglWqP9ijo=
=K9/N
-----END PGP SIGNATURE-----





Thread