ietf-openpgp
[Top] [All Lists]

Re: Shortcomings of current schemes (Was: One-pass signatures)

1998-07-26 07:28:52
-----BEGIN PGP SIGNED MESSAGE-----

In <199807261417(_dot_)QAA13184(_at_)moon(_dot_)campus(_dot_)luth(_dot_)se>, on 
07/26/98 
   at 04:17 PM, "Tony L. Svanstrom" <tony(_at_)svanstrom(_dot_)com> said:

That should also be a lot better from a security point of view; shouldn't
it?

As it is today it would be easy for my employer and/or government to keep
copies of all communication that enters and leaves their network; that
information could be used to create a "map" of my network of friends. If
we were all using PGP they wouldn't be able to read what we write, and it
would be very easy to set up and use some kind of remailer; but even if
we were to do all that they still would be able to create that "map" by
searching all e-mails for our signatures.

I'd say that this is a big security mistake. To most of us this is not
something that we have to care about, but think about what a government
could do. A network of people trying to establish a democracy in their
country might feel safe because they are using PGP, but just because they
are using PGP the government might now about every single one of them
even though that they are using remailers.

If you don't want your signature retained on a document then don't sign
it!!

- -- 
- ---------------------------------------------------------------
William H. Geiger III  http://www.openpgp.net
Geiger Consulting    Cooking With Warp 4.0

Author of E-Secure - PGP Front End for MR/2 Ice
PGP & MR/2 the only way for secure e-mail.
OS/2 PGP 5.0 at: http://www.openpgp.net/pgp.html
- ---------------------------------------------------------------
 
Tag-O-Matic: How do you make Windows faster?  Throw it harder!

-----BEGIN PGP SIGNATURE-----
Version: 2.6.3a-sha1
Charset: cp850
Comment: Registered_User_E-Secure_v1.1b1_ES000000

iQCVAwUBNbs+249Co1n+aLhhAQHmywP/TcEpY1kT4eWyKpkE4rFTkjlibsCoIDB+
XgmYKDL6B+tnC4o8MRm9plEIf162OvWCL2Fxfd54Y7Di4oRLSGaKcmTXJ6avpMu2
yAqVUu8zE/2JFL2X/JLaDaxdRX48tJzjBD0lWjIz0LskQM9vIlJTwMgBUH0pkSLT
QofRYEKRSUg=
=rPwg
-----END PGP SIGNATURE-----