NODE 4ceffbf1Is this true...
Ted Garrett <teddygee@visi.net>Thu, 11 Jan 1996 04:45:02 +0800
-----BEGIN PGP SIGNED MESSAGE-----
Being new to crypto subjects, I guess I'm pretty gullable about how much one
should use encryption in general. I remember reading somewhere that it
would probably be best for the 'world as a whole' if everyone used
encryption whenever possible so that when you DO send encrypted messages
that actually contain information you want kept secret, it doesn't stick out
like a sore thumb.
To that end, I should imagine that once I have a person's pgp key, they may
well never see another cleartext message from me again! Of course, now I'm
trying to figure out how to use the anonymous remailers and such. Boy, this
is fun!
Of course, the fact that my government doesn't really care for the idea of
publicly available cryptography makes it even more enticing.
- --
Ted Garrett
Live Systems Integration
-----BEGIN PGP SIGNATURE-----
Version: 2.6.2
iQEVAwUBMPQhKc1+l8EKBK5FAQGkqgf7BN6GxJ5MHCAJZwfuS1JjNNQanT471L3O
0VEhkg0S0GG+827Swly3Bi+0BABcGcQatBSMGFRiecjIEzrRRa/6ME4tAr8qT/EW
DXVksWk4Bf6ax8uIF1uPf0uIOeQHOuCZwVnH7uHYCpaOMaMeTVobbyLeT30Gc5Ou
YhRIeyUvTazqlWqQaNSLSJX1no9Ph0R6WnDMUYGXof+VXgLw//jddcEfMYYn24hA
C8860mAbzke95iuACGcu6hzrr6njVaPMJHqyHb8kZwOjuESzDxZw0cYxt3VRPE72
NXqHzati0Rc/uzpx9FXV5lopRd0fFQUBOK75w0PA3Q5h/RQE6cvj+g==
=SQ81
-----END PGP SIGNATURE-----
NODE dcccfa1cRe: Is this true...
Rich Graves <llurch@networking.stanford.edu>Wed, 10 Jan 96 13:01:40 PST
On Wed, 10 Jan 1996, Ted Garrett wrote:
> Being new to crypto subjects, I guess I'm pretty gullable about how much one
> should use encryption in general. I remember reading somewhere that it
> would probably be best for the 'world as a whole' if everyone used
> encryption whenever possible so that when you DO send encrypted messages
> that actually contain information you want kept secret, it doesn't stick out
> like a sore thumb.
>
> To that end, I should imagine that once I have a person's pgp key, they may
> well never see another cleartext message from me again!
The liability of that is a little inconvenience, which can lead to
laziness and insecurity.
I usually read mail on a highly visible multiuser UNIX system of which I
am not the sysadmin and that has been broken into several times. If you
send me encrypted mail, then I either need to keep my key, type my
passphrase, etc. on this insecure system, or download the mail to a PC or
Mac, which isn't always possible.
Most sessions of mine to this host are encrypted in kerberos or ssh, but
not all.
Sending unencrypted mail is rather like sending a postcard. But postcards
are fine a lot of the time.
Being too cavalier about the use of PGP is rather like putting multiple
deadbolts on the front door to your house, but accidentally dropping
copies of your house keys wherever you go.
-rich