NODE 618196f0the netscape/ssl controversy
Avi Harris Baumstein <avi@clas.ufl.edu>Tue, 13 Dec 94 06:48:50 PST
have to get my two cents in:
netscape has a proposal that secures the *transport* of files. pgp and
the like secure the actual files themselves. the question that will
have to be answered is "which method of security is more valuable to
the internet as a whole?"
of course i have made up my mind, but i'll waste some space and share
those thoughts here.
i sit on a committee at the college of agriculture here at uf, where
we are discussing how to implement the web. many of these people come
from beauracratic and publishing (the college publishes lots)
backgrounds. they want control and accountability. they don't want
someone to download some chemical information, believing that it is
correct (as certified by the university), but in actuality that
information was forged. i (and a few others) brought up digital
signatures as a way of guaranteeing authenticity of documents. but
this would an awful pain to implement, simply because the products do
not support it.
ssl can not provide this. ssl can guarantee that the document was not
modified from the server it originated from until i got it. but who is
to say that the server i got it from was the authoritative server?
that's merely one example of where ssl provides no added benefit, but
other encryption technologies do.
so what is a better solution?
i would choose a mime multipart using pgp or some other cryptographic
method. if integrated into the web client, it could be just as
seamless to the user, but now instead of encrypting the link between
two computers, it encrypts (or signs) the document itself, since
that's what i'm really interested in anyway (is the document). i could
care little about the link - and that's the premise of the internet,
that the link is unimportant as long as it works.
so while ssl may well be a wonderful protocol, it does not address the
problems that many cypherpunks see as being real. i think it would do
netscape good to listen to and consider the views of many on this
list, as they have many genuinely good ideas, even if they choose a
confrontational manner.
-avi
NODE 0a79e406Re: the netscape/ssl controversy
"Perry E. Metzger" <perry@imsi.com>Tue, 13 Dec 94 07:55:14 PST
Avi Harris Baumstein says:
> so what is a better solution?
>
> i would choose a mime multipart using pgp or some other cryptographic
> method.
There is now a "Security Multiparts" document that tells you just how
to do this. Check the internet drafts directory...
Perry
NODE 4ccbe3b6Re: the netscape/ssl controversy
jamesd@netcom.com (James A. Donald)Tue, 13 Dec 94 11:06:07 PST
Avi Harris Baumstein writes
> netscape has a proposal that secures the *transport* of files. pgp and
> the like secure the actual files themselves. the question that will
> have to be answered is "which method of security is more valuable to
> the internet as a whole?"
No.
Both methods are valuable.
Netscape has provided a screwdriver. People are screaming at
them for not producing a hammer. They are planning the hammer
later.
We do not have to choose. The more tools, the better.
The correct response is "Thanks, but what we really want
is a hammer."
Not "You stupid assholes, if you had the brains of a
turnip you would know that a screwdriver is THE WRONG
TOOL AND THE RIGHT TOOL IS A HAMMER, YOU HALF WITTED
MORONS."
--
---------------------------------------------------------------------
We have the right to defend ourselves and our
property, because of the kind of animals that we James A. Donald
are. True law derives from this right, not from
the arbitrary power of the omnipotent state. jamesd@netcom.com