1997-11-03 - re: Speech as co-conspiring? I don’t think so.

Header Data

From: Secret Squirrel <nobody@secret.squirrel.owl.de>
To: cypherpunks@cyberpass.net
Message Hash: a71115f5c6da08eaf328b7cc08c3816eeac83ef228226b1bf2372c24e29427df
Message ID: <439400e9f3604a48781f48485a000403@squirrel>
Reply To: N/A
UTC Datetime: 1997-11-03 00:27:32 UTC
Raw Date: Mon, 3 Nov 1997 08:27:32 +0800

Raw message

From: Secret Squirrel <nobody@secret.squirrel.owl.de>
Date: Mon, 3 Nov 1997 08:27:32 +0800
To: cypherpunks@cyberpass.net
Subject: re: Speech as co-conspiring? I don't think so.
Message-ID: <439400e9f3604a48781f48485a000403@squirrel>
MIME-Version: 1.0
Content-Type: text/plain



-----BEGIN PGP SIGNED MESSAGE-----

Monty Cantspell, Editor in Chief of Groan Magazine, wrote:
>> There was a discussion a little while ago suggesting that toad.com had
>> been compromised by people who were sowing dissension by partially
>> distributing certain messages.  Had toad signed all of its messages,
>> it would be possible to obtain evidence supporting this hypothesis
>> without relying entirely on the word of people we may not know.
>
>How do signed messages deal with the incompleat distribushun problem?
>If legit signed messages are not sent to half the list, what does the
>sig gain us?

When Attila says "I have this message from the list" and it has a
valid signature, it makes things considerably more interesting because
we don't have to trust Attila very much.  For instance, it may give
the owner of the signing key incontrovertible proof that his machine
was compromised.  If we have several examples of messages which are
slightly different from each other and are signed by the list key, we
know that an attack was mounted, although we may not know by whom.

>> Had somebody compromised toad, they would still have to correctly sign
>> messages.
>
>But, depending on the compromise, this could be possible.

I phrased that badly.  What I meant to say was that the person who
compromised the machine may be able to sign messages, but he or she
will still have to sign all the messages going out.  Which means that
they can be compared later, which may show incontrovertible proof that
Something Is Wrong And It Is Wrong In A Most Interesting Way.

Monty Cantsin
Editor in Chief
Smile Magazine
http://www.neoism.org/squares/smile_index.html
http://www.neoism.org/squares/cantsin_10.htm

-----BEGIN PGP SIGNATURE-----
Version: 2.6.2

iQEVAwUBNFzqp5aWtjSmRH/5AQFAsgf7B2F4xDdQZc4koltSO1exTkAGIzxH8nCP
7lh5r2P3vPhC1BfxkCMr3+kTIAuTcXPhvkmGxXNGjud+wqPOW/BYDPUfyjGDQ/rD
TZOM23iqVYZIfiiyEdl3DbqmiIv7W0Zrs8b9yhlDnjWPXGnqmgu5QV8LM3QHEEKk
nOhKz+qm3cv4UNI9wK87+PjmFKNN9JZCq3WsFCYPI9QSCJR9qgZ7YXnGAPGs7dbG
CYRhRYRUMPYBha2RfROvkU5xWH32iRE0bdLQ/uxCjL0vZxoMSq5gDMAjm1Hu02+L
8qTsyCK/LeCRBwtNBCHTO70E71lsV2jD+03Xcxm3SzYHnNo5G6RUHQ==
=x/pi
-----END PGP SIGNATURE-----







Thread