Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > alt.os.linux > #50905

Re: Good example why business emails should be PGP'ed

From Dan Purgert <dan@djph.net>
Newsgroups alt.os.linux
Subject Re: Good example why business emails should be PGP'ed
Date 2018-09-24 16:40 +0000
Organization A noiseless patient Spider
Message-ID <slrnpqi4rm.6s3.dan@xps-linux.djph.net> (permalink)
References <309a76cf8bed5568f4d87d680befa055@msgid.frell.theremailer.net> <g0quv3Fhk7dU1@mid.individual.net> <slrnpqhf19.6s3.dan@xps-linux.djph.net> <pob1v4$udi$1@tncsrv09.home.tnetconsulting.net>

Show all headers | View raw


Grant Taylor wrote:
> On 09/24/2018 04:27 AM, Dan Purgert wrote:
>> PGP uses the "Web of Trust" model, rather than the x.509 "Chain of 
>> Trust", but it does rely on you trusting people who in turn trust the 
>> signer's key.  For example, none of you likely trust the signature on 
>> this message very far :).
>
> That's one way to use PGP.  Another is to exchange public key signatures 
> / hashes via Out of Band methods with the party in question.

Oh right, forgot about that one this morning.

>
>> To be fair, that's the same problem with S/MIME -- no telling whether 
>> or not the machine itself was compromised.
>
> IMHO neither PGP nor S/MIME are meant to defend against a compromised 
> machine.  -  If you're worried about that, you have bigger issues.

Indeed.

> [...]
>> Honestly, the best way around that is physical -- i.e. "come down to 
>> the office and ...";
>
> You don't have to conduct all transactions in person.  That's also 
> subject to disguises.
>
> You need to establish a seed of trust in person (or over the phone) and 
> then use that seed of trust for remote communications.

Yeah, I never said that physical was the *only* way to conduct business.

> [...]
>> rather than acting on instructions received via electronic means (in fact, 
>> that's how several businesses I interact with are - you either have to 
>> walk into their office, or use the phone [although phone instructions 
>> can be rejected if they're "doing too much"]).
>
> IMHO it's better to establish a seed of trust that can easily be 
> leveraged remotely to provide better security and enable remote 
> transactions.

Oh, the businesses do both - but they only extend the "seed of
trust(tm)" so far.  Like my finance/ insurance people will accept a lot
of instructions over the phone; but "hey, I need to put >$10k into
$account" is a "we can't do that over the phone" transaction.

Realistically, that *might* be banking regulations moreso than anything,
never thought to dig into it further (because, let's face it, if I have
$10k to be moving around in one go, I probably have a lot of other
paperwork to fill out).


-- 
|_|O|_| Registered Linux user #585947
|_|_|O| Github: https://github.com/dpurgert
|O|O|O| PGP: 05CA 9A50 3F2E 1335 4DC5  4AEE 8E11 DDF3 1279 A281

Back to alt.os.linux | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

Good example why business emails should be PGP'ed Fritz Wuehler <fritz@spamexpire-201809.rodent.frell.theremailer.net> - 2018-09-23 19:45 +0000
  Re: Good example why business emails should be PGP'ed "Carlos E. R." <robin_listas@es.invalid> - 2018-09-23 22:03 -0400
    Re: Good example why business emails should be PGP'ed Dan Purgert <dan@djph.net> - 2018-09-24 10:27 +0000
      Re: Good example why business emails should be PGP'ed Richard Kettlewell <invalid@invalid.invalid> - 2018-09-24 14:11 +0100
        Re: Good example why business emails should be PGP'ed Dan Purgert <dan@djph.net> - 2018-09-24 15:20 +0000
          Re: Good example why business emails should be PGP'ed Richard Kettlewell <invalid@invalid.invalid> - 2018-09-24 17:49 +0100
      Re: Good example why business emails should be PGP'ed Grant Taylor <gtaylor@tnetconsulting.net> - 2018-09-24 09:57 -0600
        Re: Good example why business emails should be PGP'ed Dan Purgert <dan@djph.net> - 2018-09-24 16:40 +0000
    Re: Good example why business emails should be PGP'ed anon <noreply@mixnym.net> - 2018-09-24 07:48 -0500
      Re: Good example why business emails should be PGP'ed "Carlos E. R." <robin_listas@es.invalid> - 2018-09-24 13:18 -0400
        Re: Good example why business emails should be PGP'ed anon <noreply@mixnym.net> - 2018-09-25 08:16 -0500
          Re: Good example why business emails should be PGP'ed "Carlos E. R." <robin_listas@es.invalid> - 2018-09-25 10:26 -0400
            Re: Good example why business emails should be PGP'ed Wouter Verhelst <w@uter.be> - 2018-09-25 17:17 +0200
              Re: Good example why business emails should be PGP'ed "Carlos E. R." <robin_listas@es.invalid> - 2018-09-26 14:16 -0400
                Re: Good example why business emails should be PGP'ed nospam <nospam@nospam.invalid> - 2018-09-26 14:24 -0400
                Re: Good example why business emails should be PGP'ed "Carlos E. R." <robin_listas@es.invalid> - 2018-09-26 14:47 -0400
                Re: Good example why business emails should be PGP'ed nospam <nospam@nospam.invalid> - 2018-09-26 14:56 -0400
                Re: Good example why business emails should be PGP'ed "Carlos E. R." <robin_listas@es.invalid> - 2018-09-26 22:20 -0400
                Re: Good example why business emails should be PGP'ed nospam <nospam@nospam.invalid> - 2018-09-27 00:43 -0400
                Re: Good example why business emails should be PGP'ed "Carlos E. R." <robin_listas@es.invalid> - 2018-09-27 11:21 -0400
                Re: Good example why business emails should be PGP'ed nospam <nospam@nospam.invalid> - 2018-09-27 11:52 -0400
                Re: Good example why business emails should be PGP'ed "Carlos E. R." <robin_listas@es.invalid> - 2018-09-27 12:10 -0400
                Re: Good example why business emails should be PGP'ed nospam <nospam@nospam.invalid> - 2018-09-27 12:15 -0400
                Re: Good example why business emails should be PGP'ed "Carlos E. R." <robin_listas@es.invalid> - 2018-09-27 14:31 -0400
                Re: Good example why business emails should be PGP'ed Frank Slootweg <this@ddress.is.invalid> - 2018-09-27 20:07 +0000
                Re: Good example why business emails should be PGP'ed nospam <nospam@nospam.invalid> - 2018-09-27 16:39 -0400
                Re: Good example why business emails should be PGP'ed "Carlos E. R." <robin_listas@es.invalid> - 2018-09-28 09:45 -0400
                Re: Good example why business emails should be PGP'ed nospam <nospam@nospam.invalid> - 2018-09-28 09:52 -0400
                Re: Good example why business emails should be PGP'ed "Carlos E. R." <robin_listas@es.invalid> - 2018-09-28 14:22 -0400
                Re: Good example why business emails should be PGP'ed nospam <nospam@nospam.invalid> - 2018-09-28 14:26 -0400
                Re: Good example why business emails should be PGP'ed "Carlos E. R." <robin_listas@es.invalid> - 2018-09-28 15:43 -0400
                Re: Good example why business emails should be PGP'ed nospam <nospam@nospam.invalid> - 2018-09-28 15:54 -0400
                Re: Good example why business emails should be PGP'ed The Natural Philosopher <tnp@invalid.invalid> - 2018-09-27 06:52 +0100
                Re: Good example why business emails should be PGP'ed "Carlos E. R." <robin_listas@es.invalid> - 2018-09-27 11:22 -0400
  Re: Good example why business emails should be PGP'ed Mike Easter <MikeE@ster.invalid> - 2018-09-24 08:37 -0700

csiph-web