Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > uk.comp.security > #51 > unrolled thread

A potential possibility of improvement of PKI for personal communications

Started byMok-Kong Shen <mok-kong.shen@t-online.de>
First post2015-08-19 20:55 +0200
Last post2015-08-21 13:48 +0200
Articles 4 — 2 participants

Back to article view | Back to uk.comp.security


Contents

  A potential possibility of improvement of PKI for personal communications Mok-Kong Shen <mok-kong.shen@t-online.de> - 2015-08-19 20:55 +0200
    Re: A potential possibility of improvement of PKI for personal communications Michael Uplawski <michael.uplawski@drusus.uplawski.eu> - 2015-08-20 07:52 +0200
      Re: A potential possibility of improvement of PKI for personal communications Mok-Kong Shen <mok-kong.shen@t-online.de> - 2015-08-20 19:32 +0200
    Re: A potential possibility of improvement of PKI for personal communications Mok-Kong Shen <mok-kong.shen@t-online.de> - 2015-08-21 13:48 +0200

#51 — A potential possibility of improvement of PKI for personal communications

FromMok-Kong Shen <mok-kong.shen@t-online.de>
Date2015-08-19 20:55 +0200
SubjectA potential possibility of improvement of PKI for personal communications
Message-ID<mr2jer$9a4$1@news.albasani.net>
In countries like Germany each citizen has an identity card that is
issued by the registration authority. Since the identity of a person is
thus in a sense created by that authority, why not let it also to
directly certify the public key of any citizen who desires to employ
asymmetric encryption? I mean the person would on that occasion have
his identity be once again checked by the authority (presumably much
better, certainly not worse than, any common CAs) and then have his
public key be entered (for a moderate charge) into a list of public
keys that is freely accessible to the public at computer terminals of
all offices of the registration authority. This way, the issue of trust
on the common CAs (or their equivalents) could be avoided.

M. K. Shen

[toc] | [next] | [standalone]


#52

FromMichael Uplawski <michael.uplawski@drusus.uplawski.eu>
Date2015-08-20 07:52 +0200
Message-ID<slrnmtaqog.3br.michael.uplawski@drusus.uplawski.eu>
In reply to#51
On Wed, 19 Aug 2015 20:55:26 +0200,
Mok-Kong Shen <mok-kong.shen@t-online.de> wrote:
>  This way, the issue of trust
> on the common CAs (or their equivalents) could be avoided.

I think you misunderstood the web of trust.

>
> M. K. Shen


-- 
GnuPG/OpenPGP  4096R/3216CF02 2013-11-15 [expires: 2015-11-15]
sub   4096R/2751C550 2013-11-15 [expires: 2015-11-15]

[toc] | [prev] | [next] | [standalone]


#53

FromMok-Kong Shen <mok-kong.shen@t-online.de>
Date2015-08-20 19:32 +0200
Message-ID<mr52uo$uau$1@news.albasani.net>
In reply to#52
Am 20.08.2015 um 07:52 schrieb Michael Uplawski:
> On Wed, 19 Aug 2015 20:55:26 +0200,
> Mok-Kong Shen <mok-kong.shen@t-online.de> wrote:
>>   This way, the issue of trust
>> on the common CAs (or their equivalents) could be avoided.
>
> I think you misunderstood the web of trust.

For persons who are sufficiently mistrustful, how could
a web of trust function at all? There are plenty of people
nowadays who don't even well trust their near relatives. For
a group of people that well trust one another, there is
in general also no problem of secure distribution of public
keys and having one person of the group to work as CA,
if necessary.

M. K. Shen


[toc] | [prev] | [next] | [standalone]


#54

FromMok-Kong Shen <mok-kong.shen@t-online.de>
Date2015-08-21 13:48 +0200
Message-ID<mr735i$qo3$3@news.albasani.net>
In reply to#51
Am 19.08.2015 um 20:55 schrieb Mok-Kong Shen:
>
> In countries like Germany each citizen has an identity card that is
> issued by the registration authority. Since the identity of a person is
> thus in a sense created by that authority, why not let it also to
> directly certify the public key of any citizen who desires to employ
> asymmetric encryption? I mean the person would on that occasion have
> his identity be once again checked by the authority (presumably much
> better, certainly not worse than, any common CAs) and then have his
> public key be entered (for a moderate charge) into a list of public
> keys that is freely accessible to the public at computer terminals of
> all offices of the registration authority. This way, the issue of trust
> on the common CAs (or their equivalents) could be avoided.

I like to quote below a follow-up to my post in comp.misc.

M. K. Shen

---------------------------------------------------------------------

That's how they work in Finland — in theory:

    <URL: http://vrk.fi/default.aspx?id=21>

In practice, online identification is done through the Finnish banks'
commercial authentication system.

    <URL: https://en.wikipedia.org/wiki/TUPAS>


Marko

[toc] | [prev] | [standalone]


Back to top | Article view | uk.comp.security


csiph-web