NODE 2979822cRe: Certificates, Attributes, Web of Trust
tcmay@got.net (Timothy C. May)Thu, 5 Oct 95 10:29:47 PDT
I have often said "You are your key." That is, keys have priority over
names, even True Names. The biometric True Name identity of a person
holding a key is only _another attribute_ of the key. Maybe important,
maybe not. It depends on the nature of the transaction.
But I go further: a huge number of interesting applications of strong
crypto have no connections at all with physical persons, let alone with
True Names. Agents in computer transactions, applets fired across networks,
agoric entities in computational ecologies, BlackNet sorts of markets, and
on and on.
The notion that a cryptographic key needs to be tied to a physical person
is deeply flawed.
The talk of certification authorities is OK, so long as the practice is
_completely_ and "strongly" voluntary (*).
(* I think maybe we need a term like "strongly voluntary," to parallel
"strong crypto." A key escrow system which can have arbitrary escrow
holders--company lawyers, grandmothers, computers in other buildings,
etc.--is "strongly voluntary." A government-sanctioned program which
authorizes, approves, regulates, and controls escrow holders is *not*. GAK
is not strongly voluntary, even though it will be sold as a "voluntary"
system.)
--Tim May
Views here are not the views of my Internet Service Provider or Government.
---------:---------:---------:---------:---------:---------:---------:----
Timothy C. May | Crypto Anarchy: encryption, digital money,
tcmay@got.net 408-728-0152 | anonymous networks, digital pseudonyms, zero
Corralitos, CA | knowledge, reputations, information markets,
Higher Power: 2^756839 | black markets, collapse of governments.
"National borders are just speed bumps on the information superhighway."
NODE f3623d1aRe: Certificates, Attributes, Web of Trust
Jeff Weinstein <jsw@netscape.com>Thu, 5 Oct 95 12:15:15 PDT
Timothy C. May wrote:
>
> I have often said "You are your key." That is, keys have priority over
> names, even True Names. The biometric True Name identity of a person
> holding a key is only _another attribute_ of the key. Maybe important,
> maybe not. It depends on the nature of the transaction.
>
> But I go further: a huge number of interesting applications of strong
> crypto have no connections at all with physical persons, let alone with
> True Names. Agents in computer transactions, applets fired across networks,
> agoric entities in computational ecologies, BlackNet sorts of markets, and
> on and on.
>
> The notion that a cryptographic key needs to be tied to a physical person
> is deeply flawed.
>
> The talk of certification authorities is OK, so long as the practice is
> _completely_ and "strongly" voluntary (*).
How about if the systems allows you to get a certificate that
has any name in it that you want, where the issuer makes no
claims about the identity of the owner of the certificate?
How about if the software lets the user decide which CAs they
will accept certificates from? Given these two features,
would you still consider requiring a certificate to be bad?
--Jeff
--
Jeff Weinstein - Electronic Munitions Specialist
Netscape Communication Corporation
jsw@netscape.com - http://home.netscape.com/people/jsw
Any opinions expressed above are mine.