1993-09-06 - Re: Key signing, authentication

From: J. Michael Diehl <mdiehl@triton.unm.edu>
To: cdodhner@indirect.com (Christian D. Odhner)
UTC Datetime: 1993-09-06 20:51:26 UTC
Raw Date: Mon, 6 Sep 93 13:51:26 PDT

From: J. Michael Diehl <mdiehl@triton.unm.edu>
Date: Mon, 6 Sep 93 13:51:26 PDT
To: cdodhner@indirect.com (Christian D. Odhner)
Subject: Re: Key signing, authentication
According to Christian D. Odhner:
> Recently there was some discussion about when to sign somebody's public
> key and when not to. Does anybody have a short, to the point set of
> guidelines on when it is ok to sign? I think minimum requirements to sign
> would most likely be receiveing that key from the owner both on and off
> the net. That way somebody on the net who is doing man-in-the-middle type
> attacks is thwarted, as is somebody who gives you the key off the net with
> a false net-id. Anyway, I'm sure there's more to it than that, like are
> phone calls ok? I mean, how did you get the # anyway? And what about
> meeting the person in the flesh? How do you know they are the same person
> you talk to on the net? Thinking too much about this could make a person
> .realy. paranoid!

Well, I think I started that thread with a query.  I got lots of discussion and 
summarized the (most conservative) concensus in my .plan file.  You can read my
policy by typing finger mdiehl@triton.unm.edu.  Hope this helps.

>"The NSA can have my secret key when they pry
>it from my cold, dead, hands... But they shall
>NEVER have the password it's encrypted with!"

I love it! ;^)

