home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: sci.crypt
- Path: sparky!uunet!mcsun!Germany.EU.net!murignis!ap542!D012S436!frank
- From: frank@D012S436.sniap.mchp.sni.de ()
- Subject: Re: User authentication
- Message-ID: <1992Aug28.140033.466@sniap.mchp.sni.de>
- Sender: news@sniap.mchp.sni.de (News Admin)
- Organization: Siemens-Nixdorf AG
- References: <19253.Aug2700.31.1692@virtualnews.nyu.edu>
- Date: Fri, 28 Aug 92 14:00:33 GMT
- Lines: 40
-
- brnstnd@nyu.edu (D. J. Bernstein) writes:
- : If you never ask the question ``Who are you?'' then you will never be
- : given a false answer.
- :
- : For *the overwhelming bulk* of human communication it has not proven
- : necessary to ask the question. So it is silly to design a ``public-key
- : infrastructure'' which forces people to ask the question---and suffers
- : all the attendant problems of false answers.
-
- This is O.K. if you're happy with everyone posting anonymously -
- as all you're getting is a link from the message which first
- publishes the public key to each subsequent message signed with it.
-
- So if this is interesting, how come more people don't post anonymously?
- Why is your message signed Dan Bernstein, not Guess Who?
-
- I'd say it's because your identity is important to *you*. You may
- not care who is at this end of the communication, but you sure
- as hell care about that end. I assume that you would be peeved
- if 10,000 people started placing "secure" posts associated
- with the name Dan Bernstein, for example.
-
- In fact, I'd say that the reason most people don't need to ask
- the question "who are you?", is because they already think they
- know, or they get told without asking. It's just that they are
- prepared to trust the answer with very little evidence. Usually
- they are right. I'd say your name really is Dan Bernstein,
- for example. And I didn't ask, you told me.
-
- Actually, I'm playing Devil's advocate a little here - I
- do think there is a place for anonymity in a secure newsgroup.
- But I also see applications for secure newsgroups based on
- real world identities. Also, if the anonymity is to have
- any real value, you would have to do something to prevent
- tracing through the posters mail address.
- --
- Frank O'Dwyer Disclaimer:
- Siemens-Nixdorf AG I will deny everything
- Tel. : +49 (89) 636-40639 Fax. : +49 (89) 636-45860
- e-mail: Frank.ODwyer@sniap.mchp.sni.de
-