home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!gatech!darwin.sura.net!wupost!micro-heart-of-gold.mit.edu!bu.edu!transfer!ellisun.sw.stratus.com!cme
- From: cme@ellisun.sw.stratus.com (Carl Ellison)
- Newsgroups: sci.crypt
- Subject: Re: User authentication
- Message-ID: <6114@transfer.stratus.com>
- Date: 2 Sep 92 19:11:25 GMT
- References: <1992Aug31.135512.16204@sniap.mchp.sni.de> <6069@transfer.stratus.com> <1992Sep1.194045.1943@bcars64a.bnr.ca>
- Sender: usenet@transfer.stratus.com
- Organization: Stratus Computer, Software Engineering
- Lines: 37
-
- In article <1992Sep1.194045.1943@bcars64a.bnr.ca> schow@bqneh23.bnr.ca (Stanley T.H. Chow) writes:
- >>And, as I said, once you have a public key account, I don't care what
- >>pronounceable name you use. I (the bank) will ignore it. The only thing
- >>which matters is the public key.
- >
- >--------------------
- >
- >Lost Key alert:
- >
- >It has come to our attention that our private key has been
- >lost. Please stop using the old public key at once and use this
- >new key instead "&*(413nmlfs09uln1143".
- >
- >CEO of IBM
- >
- >----------------------
- >
- >Can I now transfer some money?
-
- Not from my bank, you can't.
-
- This is one reason "How To Share a Secret" (Adi Shamir, CACM, Nov 79, p612)
- was so important. If you really lose your key, I guess I get to keep the
- money. :-)
-
- Actually, being a user-friendly bank, I will certainly let you define
- synonyms for your public key. All you have to do is send the request,
- listing both public keys, signed twice, once by each key. I'll let you
- list as many synonyms (aliases) as you want to bother listing -- to cover
- for the case when a key is lost. Being really friendly, I won't even
- charge you for my having to store these relationship messages. I'll lump
- that in with the cost of doing business.
-
- I'll also accept commands of the form: 'the private key for
- "&*(413nmlfs09uln1143" has possibly been stolen -- stop honoring it.' --
- but of course, that command has to be signed in one of the alias keys, in
- order to prove it's not a forgery.
-