home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!ferkel.ucsb.edu!taco!rock!concert!uvaarpa!darwin.sura.net!zaphod.mps.ohio-state.edu!swrinde!emory!ogicse!psgrain!puddle!f93.n104.z1.fidonet.org!Zhahai.Stewart
- From: Zhahai.Stewart@f93.n104.z1.fidonet.org (Zhahai Stewart)
- Newsgroups: comp.org.eff.talk
- Subject: Key Registration; authentication vs encryption
- Message-ID: <18684.2B02FE98@puddle.fidonet.org>
- Date: 10 Nov 92 19:34:00 GMT
- Article-I.D.: puddle.18684.2B02FE98
- Sender: ufgate@puddle.fidonet.org (newsout1.26)
- Organization: FidoNet node 1:104/93 - Adelante, Boulder CO
- Lines: 36
-
-
- Even if I disagree on whether the tradeoff in privacy is worth it, I
- can see the point of those, like Denning, who are seeking a compromise
- which could allow law enforcement to acquire private keys under court
- order, by analogy with wiretapping.
-
- This however also leaves open a second question which hasn't yet been
- discussed here. Some public key systems (including RSA) also provide
- message authentication. Anyone who has your private key, in such
- schemes, can in effect create an undetectable forgery of your "legal
- signature". Given past "dirty tricks" campaigns (by the FBI and
- others), this could be a mighty temptation. It could be used for
- harassment (creating personal friction or financial ruin), or even
- to create irrefutable yet bogus "evidence", if the key was compromised
- to parties who were not officially in posession of it.
-
- The question: does *anyone* here, Ms. Denning included, see any solid
- justification for allowing the government to engage in such forgery,
- or "spoofing"? Is there any legitimate need for this, within law
- enforcement?
-
- If not, then I would expect the "key registry" proposals to include the
- concept of using dual key pairs: one which is used for encryption, and
- whose secret key could be revealed by court order, and one which is used
- for authentication, with no registration required, and with no court
- authority to compel release of the secret half.
-
- I still believe that key registration is a bad idea, and must be opposed.
- But I hope that such proposals will nevertheless continue to be debated,
- and refined, so as to focus the attention on the real issues.
- ~z~
-
-
- --
- uucp: uunet!m2xenix!puddle!104!93!Zhahai.Stewart
- Internet: Zhahai.Stewart@f93.n104.z1.fidonet.org
-