[ale] emailing public dsa key (good, bad or ugly?)
Robert Reese
ale at sixit.com
Thu Jan 26 21:47:10 EST 2006
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
*********** REPLY SEPARATOR ***********
On 1/25/2006 at 2:37 PM David Corbin wrote:
>On Wednesday 25 January 2006 06:52 pm, Michael Hirsch wrote:
>> Why bother? Why not just send the public key? Isn't that why it's
>called
>> "public"? It should be safe to publish the key in an newspaper or blog.
>> Is there a risk we haven't heard of?
>>
>> You solution requires him to publish his public GPG key. Doesn't the
>same
>> question apply?
>
>The issue, I think, is one of idenitity/integrity. How does the reciever
>know
>the key he recieves has not been "tweaked" during the sending? That is,
>it's
>not that the public key is "something to hide", it's just something to be
>SURE is from who you think it's from.
That's the difference between "Validity" and "Trust". The definition of
this is 'switched' from what you'd instinctively think. Anyway, here is a
link to get better info than I'd ever be able to give:
<http://www.gnupg.org/gph/en/manual.html#AEN335>
Cheers,
Robert~
-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.0.4 (Build 4042)
Comment: No one has the right to not be offended!
iQA/AwUBQ9mJEbw8BOWncaQMEQLTwwCg8AZCP5cfahMpXHEA9YEuwIIaEEEAniiS
pRosn2xKog14FWrX4uGmwpWm
=4ZjK
-----END PGP SIGNATURE-----
SIXIT Consulting
H: 770-320-0181 or (478) 599-1300
Cell: 678-438-6955 or (478) 599-1301
Fax: 866-355-3720 (Toll-Free)
2907-I Watson Blvd
#308
Warner Robins, GA 31093-8535
United States
------------------------------------------------------
* Microsoft is NOT a standard. *
------------------------------------------------------
NOTICE: With respect to all communications you make to any sixit.com email address, including but not limited to feedback, questions, comments, suggestions and the like: (a) you shall have no right of confidentiality in your communications and SIXIT Consulting shall have no obligation to protect your communications from disclosure; (b) SIXIT Consulting shall be free to reproduce, use, disclose and distribute your communications to others without limitation and without expectation of compensation to you and without notice to you; and (c) SIXIT Consulting shall be free to use without any expectation of compensation to you any ideas, concepts, know-how or techniques contained in your communications for any purpose whatsoever, including but not limited to the development, production and marketing of products and services that incorporate such information; particularly if your message is of an unsolicited nature.
More information about the Ale
mailing list