// COMPLETE THREAD

Re: broadcast encryption

6 expanded posts ยท every known parent and child

NODE 807c2aeaRe: broadcast encryption
At 4:06 AM 8/9/94, Dave Horsfall wrote:

>Etc.  I've been using PGP for authenticating my packet messages for
>some months, for precisely the reasons you outlined.  I get the
>occasional "stop wasting bl**dy bandwidth" but most of the time it
>results in more PGP users.  I'm also careful to explain that PGP can't
>be used to prove I did NOT write an unsigned nasty-gram (until we get
>true authentication within the BBS, by which I hope the concept of a
>BBS will disappear :-) but it makes a strong case if I sign ALL my
>bulletins.

What I would like to see is low-level digital signatures on the level of IP
or AX.25.  IP is doable, I would think.  There's swIPe, and amateur packet
drivers for Linux, but to get people to really use it, you'd need to put it
in the software or hardware they use, like KA9Q (Hi Phil) for IP, and
AX.25.  Would it be possible to fit this into AX.25?  I don't recall that
much about the protocol, and all my packet reference materials are about
300 miles away.

Bob

--
Bob Snyder N2KGO                               MIME, PGP, RIPEM mail accepted
snyderra@post.drexel.edu                      PGP & RIPEM keys on key servers
         When cryptography is outlawed, bayl bhgynjf jvyy unir cevinpl.
NODE f66cb5b8broadcast encryption
What I would like to see is low-level digital signatures on the level of IP
   or AX.25.  IP is doable, I would think.  

What is the policy purpose for signing packets?  It will affect the
design.

Do you want to identify users, processes, or machines?

If you want to reject packets not signed or badly signed _before_
further processing, that's one way.  If you want to detect
interposition in a stream parallel to the use of that stream, that
would be another.  

Do you want each packet to carry an independent signature, or can
packets be aggregated for signature?  This is a separate problem,
since "aggregation" doesn't mean a delay, it means there is state
information carried which is involved in checking the signature.  This
question involves the abstraction level where authentication is taking
place.

Too often a particular situation is in mind and remains unspoken.
Making assumptions explicit is necessary for good design and useful
debate.

Eric
NODE 5e9dcd86Re: broadcast encryption
Eric Hughes says:
>    What I would like to see is low-level digital signatures on the
>    level of IP or AX.25.  IP is doable, I would think.  
> 
> What is the policy purpose for signing packets?  It will affect the
> design.

Anyone even making such suggestions has not been following the IPSP
standardization work...

Perry
NODE 1d6d2ef3broadcast encryption
> What is the policy purpose for signing packets?  It will affect the
   > design.

   Anyone even making such suggestions has not been following the IPSP
   standardization work...

I wasn't asking what _the_ purpose was, but rather what the purpose
the original author (coming out of the context of a radio discussion)
had in mind.  I know _lots_ of reasons for signing packets in some
way.

Eric
NODE 6ade9cf9Re: broadcast encryption
Eric Hughes says:
>    > What is the policy purpose for signing packets?  It will affect the
>    > design.
> 
>    Anyone even making such suggestions has not been following the IPSP
>    standardization work...
> 
> I wasn't asking what _the_ purpose was, but rather what the purpose
> the original author (coming out of the context of a radio discussion)
> had in mind.  I know _lots_ of reasons for signing packets in some
> way.

Oh, I understood what you were saying -- I didn't understand what the
orignal author could be looking for...

.pm
NODE 180a0820Re: broadcast encryption
On Tue, 9 Aug 1994, Perry E. Metzger wrote:

> Oh, I understood what you were saying -- I didn't understand what the
> orignal author could be looking for...

And by now I've lost track of the original discussion, so I'm not sure
whether I am the one being referred to above (I'm the one who PGP signs
all his packet radio messages, in response to Bob Snyder saying he sees
no problem with this, and Bob replied saying he'd like to see it at the
link level), and it sort of diverged from there...

Given that the FCC (and other countries' equivalents) are starting to
crack down on packet radio abuse (it's all too easy to fake someone
else's callsign) I imagine it won't be long before we Amateurs are forced
to implement some form of authentication (down to the callsign i.e. the
user).

You out there, Phil?

-- 
Dave Horsfall (VK2KFU) | dave@esi.com.au | VK2KFU @ VK2AAB.NSW.AUS.OC | PGP 2.6
Opinions expressed are mine. | E7 FE 97 88 E5 02 3C AE  9C 8C 54 5B 9A D4 A0 CD