-----BEGIN PGP SIGNED MESSAGE-----
In <199709182044(_dot_)AA07307(_at_)world(_dot_)std(_dot_)com>, on 09/18/97
at 04:44 PM, Dan Geer <geer(_at_)world(_dot_)std(_dot_)com> said:
>I asked an author of the Utah Digital Signature Act
>last week whether encryption, of and by itself, would
>constitute the legal force of signature. He said it
>would.
Hmmmm that seems a little silly to me since anyone can encrypt a
message.
Encryption alone does not provide authentication.
for clarity, he/I meant that if m is encrypted
in your private key then you've acknowledged
authorship
putting it differently, "signing" is a subset
of "encrypting", legally speaking
Nothing personal but I hope the law isn't worded that way. :(
In common disscussion of public key encryption when one talks of
"Encryption" of a message they are most definatly not speaking of
encrypting with ones secret key.
I guess one could encrypt the entire message with ones secret key and
bypass the use of the hash but it is not a practice I would recomend and
it clouds the distinction between standard "encryption" & "signatures"
from a legal standpoint.
I really feel sorry for the poor shmucks when this stuff winds up in court
and they have to explain to a jury that "no they only ment if you
encrypted with your secret key ..."
- From what I have seen of the various Digital Signature Laws they are a bad
thing.
- --
- ---------------------------------------------------------------
William H. Geiger III http://www.amaranth.com/~whgiii
Geiger Consulting Cooking With Warp 4.0
Author of E-Secure - PGP Front End for MR/2 Ice
PGP & MR/2 the only way for secure e-mail.
OS/2 PGP 2.6.3a at: http://www.amaranth.com/~whgiii/pgpmr2.html
- ---------------------------------------------------------------
-----BEGIN PGP SIGNATURE-----
Version: 2.6.3a
Charset: cp850
Comment: Registered_User_E-Secure_v1.1b1_ES000000
iQCVAwUBNCGSjI9Co1n+aLhhAQFgCQP/XFY7Yw/ZJ7Kt80xt9vtp0VvWp2bHmS02
+w8EdKI9nGNFyGEfW4UAZ7lRJo7bfvCJRjQxWuRArM/wg+nr/dTrW+SpjG4dtcz3
kIVG/pGUPrkOcs8U6EaIRAmQwibuws3E1lMqTZNZExDFFwF6T55SbS6yR1/R0ERd
1ZaWQ5l6GFQ=
=Yw4m
-----END PGP SIGNATURE-----