1993-04-28 - Re: PGP: pgp -ke

Header Data

From: Derek Atkins <warlord@Athena.MIT.EDU>
To: Chuck.Lever@umich.edu
Message Hash: dab4c6ae668323b8d1f62fcb26d6c4cec2e17cd6e12faf4f27176a08c4701cd1
Message ID: <9304282146.AA00918@stage8>
Reply To: <9304281852.AA00450@toad.com>
UTC Datetime: 1993-04-28 21:46:47 UTC
Raw Date: Wed, 28 Apr 93 14:46:47 PDT

Raw message

From: Derek Atkins <warlord@Athena.MIT.EDU>
Date: Wed, 28 Apr 93 14:46:47 PDT
To: Chuck.Lever@umich.edu
Subject: Re: PGP: pgp -ke
In-Reply-To: <9304281852.AA00450@toad.com>
Message-ID: <9304282146.AA00918@stage8>
MIME-Version: 1.0
Content-Type: text/plain


Hi.

A signature on a key is a cryptographic signature of the key and
userid.  Therefore, you cannot remove your userid from the key and
hope to keep the signatures valid.

The other problem is that once other people have your userid on your
key, which is neccessary for them to sign it, then you need to have
them remove it, too, etc.

Basically, signatures and userids currently act like viruses...  Once
they escape, its nearly impossible to contain them again....

-derek

  Derek Atkins, MIT '93, Electrical Engineering and Computer Science
     Secretary, MIT Student Information Processing Board (SIPB)
           MIT Media Laboratory, Speech Research Group
           warlord@MIT.EDU       PP-ASEL        N1NWH





Thread