NODE 06e6289cPGP: pgp -ke
Chuck Lever <cel@citi.umich.edu>Wed, 28 Apr 93 11:52:05 PDT
so, like, what's to stop me from writing a program (based on pgp source
code) which can delete user IDs from my own keys after other folks have
signed them? in fact, how *can* i change the user ID on a key after it
has been signed?
the pgp docs are unclear on how this works. can someone help me to
understand what it means exactly when a key is signed? what parts of
the key are certified by the signature?
NODE dab4c6aeRe: PGP: pgp -ke
Derek Atkins <warlord@Athena.MIT.EDU>Wed, 28 Apr 93 14:46:47 PDT
Hi.
A signature on a key is a cryptographic signature of the key and
userid. Therefore, you cannot remove your userid from the key and
hope to keep the signatures valid.
The other problem is that once other people have your userid on your
key, which is neccessary for them to sign it, then you need to have
them remove it, too, etc.
Basically, signatures and userids currently act like viruses... Once
they escape, its nearly impossible to contain them again....
-derek
Derek Atkins, MIT '93, Electrical Engineering and Computer Science
Secretary, MIT Student Information Processing Board (SIPB)
MIT Media Laboratory, Speech Research Group
warlord@MIT.EDU PP-ASEL N1NWH