home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: sci.crypt
- Path: sparky!uunet!zaphod.mps.ohio-state.edu!pacific.mps.ohio-state.edu!linac!att!princeton!raven!dla
- From: dla@raven (Don Alvarez)
- Subject: Re: Secure netnews
- Message-ID: <1992Aug27.142234.28923@Princeton.EDU>
- Originator: news@nimaster
- Sender: news@Princeton.EDU (USENET News System)
- Nntp-Posting-Host: raven.princeton.edu
- Organization: Princeton University
- References: <1992Aug18.221506.13535@Princeton.EDU> <1992Aug27.131849.13130@sniap.mchp.sni.de>
- Date: Thu, 27 Aug 1992 14:22:34 GMT
- Lines: 17
-
- In article <1992Aug27.131849.13130@sniap.mchp.sni.de> frank@D012S436.sniap.mchp.sni.de () writes:
- >
- >my site knows me well. Your site knows you.
- >
- >Therefore your site can certify (sign) your public key. Mine can
- >certify mine. ALL THAT IS REQUIRED NOW IS FOR OUR SITES TO CROSS
- >CERTIFY EACH OTHER'S KEYS. [emphasis added]
-
- And _that_ is the trick. Sure, islands of trust do exist, but unless
- that island of trust is large enough to encompass both your site and
- mine, then, then neither you nor I can trust the identity of each
- other's *site*. All you have done is pass the certification problem up
- one level from the individual to the site. All the same fundamental
- issues occur at the site level as occur at the individual level.
-
- -don
-
-