// COMPLETE THREAD

Laws recognizing digital signatures

4 expanded posts ยท every known parent and child

NODE a3544da0Laws recognizing digital signatures
I have talked to people in government and the offshore private sector here
and think Anguilla has a very good chance of passing a law making digital
signatures legally recognized, at least for corporations.  I think we
would be the first taxhaven to do so.  Currently companies use corporate
seals. 

I mentioned that there were a few other jurisdictions that had passed some
laws like this and they would like me to try to pin down which and, if
possible, get copies of the laws. 

I remember some talk about this on cypherpunks, so I am hoping someone
here can tell me which places (think there was some state) have such laws,
and if possible tell me where I can get a copy.

Thanks,

    -- Vince

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 Vincent Cate                           Offshore Information Services
 Vince@Offshore.com.ai                  http://www.offshore.com.ai/
 Anguilla, BWI                          http://www.offshore.com.ai/vince
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
NODE 3d498464Re: Laws recognizing digital signatures
At 9:24 am -0400 on 10/23/97, Vincent Cate wrote:

> I mentioned that there were a few other jurisdictions that had passed some
> laws like this and they would like me to try to pin down which and, if
> possible, get copies of the laws.
>
> I remember some talk about this on cypherpunks, so I am hoping someone
> here can tell me which places (think there was some state) have such laws,
> and if possible tell me where I can get a copy.

Funny you should ask that. There's a bunch of lawyerly traffic on
DIGSIG@VM.TEMPLE.EDU, run off of LISTSERV@VM.TEMPLE.EDU. I've sent you the
welcome message under separate cover. Of course, if you'd been subscribing
to e$pam, you'd know all of this. :-). (Of course, if I could just get some
keyword searchable archives of e$pam up and running, you wouldn't have to
subscribe to a mail-firehose like e$pam ;-)).

Take a look at:

http://www.smu.edu/~jwinn/esig.htm

Jane Winn is god. (this week anyway)

Cheers,
Bob Hettinga

-----------------
Robert Hettinga (rah@shipwright.com), Philodox
e$, 44 Farquhar Street, Boston, MA 02131 USA
"... however it may deserve respect for its usefulness and antiquity,
[predicting the end of the world] has not been found agreeable to
experience." -- Edward Gibbon, 'Decline and Fall of the Roman Empire'
The e$ Home Page: http://www.shipwright.com/
Ask me about FC98 in Anguilla!: <http://www.fc98.ai/>
NODE fcf285e0Re: Laws recognizing digital signatures
At 09:24 AM 10/23/1997 -0400, Vincent Cate wrote:
>I have talked to people in government and the offshore private sector here
>and think Anguilla has a very good chance of passing a law making digital
>signatures legally recognized, at least for corporations.  I think we
>would be the first taxhaven to do so.  Currently companies use corporate
>seals. [....]
>I mentioned that there were a few other jurisdictions that had passed some
>laws like this and they would like me to try to pin down which and, if
>possible, get copies of the laws. 

Cem Kaner <kaner@kaner.com> gave a good presentation on the legal climate 
surrounding digital signatures at is month's Cypherpunks meeting.  
There's a lot of bad legislation being proposed in various UN and US 
working groups, where "bad" includes "inflexible" and 
"favoring specific models of what a signature means" and 
"favoring the certificate authority rather than the merchant or customer
in a transaction using certified signatures" and
"limiting who can be a CA, possibly including licensing".
He's got information available at www.kaner.com and www.badsoftware.com.
You might also want to talk to Carl Ellison about his views on signatures.

The basic problem is 
- Person Alice may have a key
- Merchant Bob has an online store
- Customer X presents Bob with a key K, certified by CA Charlie,
	claiming that she's Alice, K is Alice's key,
	and downloads the merchandise from Bob.
- Alice says it wasn't her and refuses to pay Bob the bill.

So who gets stuck with the bill?  Alice?  Bob?  Charlie?
In most commercial transactions, there's a legal tradition that defines
the liability when a signature is misused or a transaction fails badly.  
With forged checks or counterfeit Federal Reserve notes, the merchant loses.
With checks written against insufficient funds, Alice is liable,
though if she doesn't have any money to collect, the merchant still loses.
With credit cards in the US, the credit card company is liable to the merchant,
whether the credit card was stolen or Alice doesn't pay; in case of theft
Alice is liable to the credit card company for $50, but it's not Bob's problem.
This is a benefit to the merchant, since he can almost always accept a payment
and make a sale, and it's a benefit to the consumer, because the merchant
will accept her payment so she can get her stuff, and it's a big pain to the
credit card companies, who lose a lot of money to fraud every year, though
of course their fee to the merchant includes that cost, as does the merchant's
price to the consumer which is higher to cover the credit card fees.

In most of the new digital signature legislation, it's being pushed by the
Certificate Authority companies, who want to make sure they're not liable,
and who generally want to stick the consumer Alice with the bill,
since it's her fault if she let her public key get misused.
Not only is consumer getting the short end of the stick on these laws,
which is Cem's interest in this topic, but so is the merchant,
because if Alice is liable, he's got to collect from her if he can;
Cem is surprised that the Sears Roebuck and similar large merchant types
haven't been actively participating in these meetings.

>From a Cypherpunks and PGP perspective, there are a bunch of problems here.
One is "what does a signature mean, and how do we represent it",
which sidetracked much of the discussion during Cem's talk.
Another is that there's a preference toward a hierarchical model of CAs,
rather than the everybody's-a-CA web-of-trust model used by PGP;
in particular, regulations on digital signatures often require CAs
to meet some set of licensing requirements, which would mean you couldn't
sign anybody's key without a license, or at least without acquiring some
liability for how they used it.  (Then of course, once CAs are licensed and
findable, they're a regulatory target - even if you can't force them to
escrow their users' keys, you can at least use them for traffic analysis,
especially if you're using certificate revocation lists.)

An entertaining problem Cem also brought up is that if he doesn't
get his keys signed by anyone, they're just keys, and mean whatever
he agrees contractually with his clients that they mean.
On the other hand, if he gets his keys signed by someone,
there's some definition of liability that may obtain from that action,
not only based on the contracts he makes with the CA, but potentially
on any regulations on CAs and digital signatures that get adopted.
				Thanks! 		Bill
Bill Stewart, stewarts@ix.netcom.com
Regular Key PGP Fingerprint D454 E202 CBC8 40BF  3C85 B884 0ABE 4639
[I'm currently having hardware problems with my main email; 
send Cc: billstewart@att.com if you need to reach me in a hurry.]
NODE 75002d13Re: Laws recognizing digital signatures
* stewarts@ix.netcom.com wrote:
>The basic problem is 
>- Person Alice may have a key
>- Merchant Bob has an online store
>- Customer X presents Bob with a key K, certified by CA Charlie,
>	claiming that she's Alice, K is Alice's key,
>	and downloads the merchandise from Bob.
>- Alice says it wasn't her and refuses to pay Bob the bill.
>
>So who gets stuck with the bill?  Alice?  Bob?  Charlie?

Bob asks Charlie, who is really behind K. Charlie must be able to point to
Alice. If he can't do that, Bob will sue him. (Like any customer fooled by a
McLain control signed and certified by Verisign, which revoke the
certificate due to a request from Microsoft.)

Alice is responsible for her key K. If X can fool Bob, he has access to the
secret part of K, so the problem goes to Alice. Alice can inform Charlie for
revoking the certificate. If she did this, the problem went to Charlie. If
he updated his public database, the problem went to Bob. If Bob did non
check nor get a real timestamp (I.e. eternity logfile), he has lost.
Otherwise he lost, because he knew, that Alice's key was comprimised before
delivery.