// COMPLETE THREAD

Is this true...

2 expanded posts ยท every known parent and child

NODE 4ceffbf1Is this true...
-----BEGIN PGP SIGNED MESSAGE-----

Being new to crypto subjects, I guess I'm pretty gullable about how much one
should use encryption in general.  I remember reading somewhere that it
would probably be best for the 'world as a whole' if everyone used
encryption whenever possible so that when you DO send encrypted messages
that actually contain information you want kept secret, it doesn't stick out
like a sore thumb.

To that end, I should imagine that once I have a person's pgp key, they may
well never see another cleartext message from me again!  Of course, now I'm
trying to figure out how to use the anonymous remailers and such.  Boy, this
is fun!

Of course, the fact that my government doesn't really care for the idea of
publicly available cryptography makes it even more enticing.

- --
Ted Garrett
Live Systems Integration


-----BEGIN PGP SIGNATURE-----
Version: 2.6.2

iQEVAwUBMPQhKc1+l8EKBK5FAQGkqgf7BN6GxJ5MHCAJZwfuS1JjNNQanT471L3O
0VEhkg0S0GG+827Swly3Bi+0BABcGcQatBSMGFRiecjIEzrRRa/6ME4tAr8qT/EW
DXVksWk4Bf6ax8uIF1uPf0uIOeQHOuCZwVnH7uHYCpaOMaMeTVobbyLeT30Gc5Ou
YhRIeyUvTazqlWqQaNSLSJX1no9Ph0R6WnDMUYGXof+VXgLw//jddcEfMYYn24hA
C8860mAbzke95iuACGcu6hzrr6njVaPMJHqyHb8kZwOjuESzDxZw0cYxt3VRPE72
NXqHzati0Rc/uzpx9FXV5lopRd0fFQUBOK75w0PA3Q5h/RQE6cvj+g==
=SQ81
-----END PGP SIGNATURE-----
NODE dcccfa1cRe: Is this true...
On Wed, 10 Jan 1996, Ted Garrett wrote:

> Being new to crypto subjects, I guess I'm pretty gullable about how much one
> should use encryption in general.  I remember reading somewhere that it
> would probably be best for the 'world as a whole' if everyone used
> encryption whenever possible so that when you DO send encrypted messages
> that actually contain information you want kept secret, it doesn't stick out
> like a sore thumb.
> 
> To that end, I should imagine that once I have a person's pgp key, they may
> well never see another cleartext message from me again!

The liability of that is a little inconvenience, which can lead to
laziness and insecurity. 

I usually read mail on a highly visible multiuser UNIX system of which I
am not the sysadmin and that has been broken into several times. If you
send me encrypted mail, then I either need to keep my key, type my
passphrase, etc. on this insecure system, or download the mail to a PC or
Mac, which isn't always possible. 

Most sessions of mine to this host are encrypted in kerberos or ssh, but 
not all.

Sending unencrypted mail is rather like sending a postcard. But postcards 
are fine a lot of the time. 

Being too cavalier about the use of PGP is rather like putting multiple
deadbolts on the front door to your house, but accidentally dropping 
copies of your house keys wherever you go.

-rich