// COMPLETE THREAD

Re: Revoking Old Lost Keys

2 expanded posts ยท every known parent and child

NODE 2529d254Re: Revoking Old Lost Keys
At 9:10 AM 1/6/96, James Black wrote:
>Hello,
>
>On Fri, 5 Jan 1996, Bruce Baugh wrote:
>
>> The problem is this: how can one spread the word that an old key is no
>> longer to be used when one no longer has the pass phrase, and cannot
>> therefore create a revocation certificate?
>
>  If there is someone that you trust (or several people), just make a
>revocation certificate and possibly cut it into pieces, and just let
>those know when to send it out, so that you don't have to rely on a
>faulty memory, and by having it in several hands they can't just send it
>out, as they don't know the other people.  Just a thought.

If one can safely and securely store a revocation certificate for later
use, why not just store the much shorter passphrase?

--Tim May

We got computers, we're tapping phone lines, we know that that ain't allowed.
---------:---------:---------:---------:---------:---------:---------:----
Timothy C. May              | Crypto Anarchy: encryption, digital money,
tcmay@got.net  408-728-0152 | anonymous networks, digital pseudonyms, zero
W.A.S.T.E.: Corralitos, CA  | knowledge, reputations, information markets,
Higher Power: 2^756839 - 1  | black markets, collapse of governments.
"National borders aren't even speed bumps on the information superhighway."
NODE 5fbd65ebRe: Revoking Old Lost Keys
-----BEGIN PGP SIGNED MESSAGE-----

Tim May writes:
> If one can safely and securely store a revocation certificate for later
> use, why not just store the much shorter passphrase?

Well, you're dealing with very different threats in the two cases AFAICS. 
With your passphrase and private key, someone can forge your signature, read
your encrypted incoming mail, etc. With your revocation certificate and 
private key, about all they can do is revoke your key and force you to
create a new one. I certainly find the latter prospect much less alarming --
by far the lesser of two evils. Heck, it's good to update keys periodically,
so they might even be doing me a favor of sorts ;)

Futplex <futplex@pseudonym.com>

-----BEGIN PGP SIGNATURE-----
Version: 2.6.2

iQEVAwUBMO65WSnaAKQPVHDZAQEIngf+OnXNLpkc4MlE+F0O24lCgso29k0cYRiW
jOHKJJfl9ryfaM/WT8eyRLIbWhO7A2qMGSF9nlRUCuhLBgQuX6tmboTwDPW3RPzq
jKbZ6LO615w0xPhZpDQO/B963sF0UOcIc0v49k1Ua6biUeEQ/0luYn7nQPD9RVDV
pb0qkk201qgVDkXXxPR+hN/HXstI0mc2+HjQjAhHiIOLyiMN3aPwGDH1XmHP5UiE
TVw+M9cAqyC863KMg+WEkIGXvdwLJ2or6QQ07i50Zwl905mSFd9+nHVx5HLbkKFa
UZvwU46zZXx069MIKHLFY2hX1ZqgR5eGGHUa6bZbMkeIjSl50IzILA==
=ssJd
-----END PGP SIGNATURE-----