Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > uk.comp.security > #51 > unrolled thread
| Started by | Mok-Kong Shen <mok-kong.shen@t-online.de> |
|---|---|
| First post | 2015-08-19 20:55 +0200 |
| Last post | 2015-08-21 13:48 +0200 |
| Articles | 4 — 2 participants |
Back to article view | Back to uk.comp.security
A potential possibility of improvement of PKI for personal communications Mok-Kong Shen <mok-kong.shen@t-online.de> - 2015-08-19 20:55 +0200
Re: A potential possibility of improvement of PKI for personal communications Michael Uplawski <michael.uplawski@drusus.uplawski.eu> - 2015-08-20 07:52 +0200
Re: A potential possibility of improvement of PKI for personal communications Mok-Kong Shen <mok-kong.shen@t-online.de> - 2015-08-20 19:32 +0200
Re: A potential possibility of improvement of PKI for personal communications Mok-Kong Shen <mok-kong.shen@t-online.de> - 2015-08-21 13:48 +0200
| From | Mok-Kong Shen <mok-kong.shen@t-online.de> |
|---|---|
| Date | 2015-08-19 20:55 +0200 |
| Subject | A potential possibility of improvement of PKI for personal communications |
| Message-ID | <mr2jer$9a4$1@news.albasani.net> |
In countries like Germany each citizen has an identity card that is issued by the registration authority. Since the identity of a person is thus in a sense created by that authority, why not let it also to directly certify the public key of any citizen who desires to employ asymmetric encryption? I mean the person would on that occasion have his identity be once again checked by the authority (presumably much better, certainly not worse than, any common CAs) and then have his public key be entered (for a moderate charge) into a list of public keys that is freely accessible to the public at computer terminals of all offices of the registration authority. This way, the issue of trust on the common CAs (or their equivalents) could be avoided. M. K. Shen
[toc] | [next] | [standalone]
| From | Michael Uplawski <michael.uplawski@drusus.uplawski.eu> |
|---|---|
| Date | 2015-08-20 07:52 +0200 |
| Message-ID | <slrnmtaqog.3br.michael.uplawski@drusus.uplawski.eu> |
| In reply to | #51 |
On Wed, 19 Aug 2015 20:55:26 +0200, Mok-Kong Shen <mok-kong.shen@t-online.de> wrote: > This way, the issue of trust > on the common CAs (or their equivalents) could be avoided. I think you misunderstood the web of trust. > > M. K. Shen -- GnuPG/OpenPGP 4096R/3216CF02 2013-11-15 [expires: 2015-11-15] sub 4096R/2751C550 2013-11-15 [expires: 2015-11-15]
[toc] | [prev] | [next] | [standalone]
| From | Mok-Kong Shen <mok-kong.shen@t-online.de> |
|---|---|
| Date | 2015-08-20 19:32 +0200 |
| Message-ID | <mr52uo$uau$1@news.albasani.net> |
| In reply to | #52 |
Am 20.08.2015 um 07:52 schrieb Michael Uplawski: > On Wed, 19 Aug 2015 20:55:26 +0200, > Mok-Kong Shen <mok-kong.shen@t-online.de> wrote: >> This way, the issue of trust >> on the common CAs (or their equivalents) could be avoided. > > I think you misunderstood the web of trust. For persons who are sufficiently mistrustful, how could a web of trust function at all? There are plenty of people nowadays who don't even well trust their near relatives. For a group of people that well trust one another, there is in general also no problem of secure distribution of public keys and having one person of the group to work as CA, if necessary. M. K. Shen
[toc] | [prev] | [next] | [standalone]
| From | Mok-Kong Shen <mok-kong.shen@t-online.de> |
|---|---|
| Date | 2015-08-21 13:48 +0200 |
| Message-ID | <mr735i$qo3$3@news.albasani.net> |
| In reply to | #51 |
Am 19.08.2015 um 20:55 schrieb Mok-Kong Shen:
>
> In countries like Germany each citizen has an identity card that is
> issued by the registration authority. Since the identity of a person is
> thus in a sense created by that authority, why not let it also to
> directly certify the public key of any citizen who desires to employ
> asymmetric encryption? I mean the person would on that occasion have
> his identity be once again checked by the authority (presumably much
> better, certainly not worse than, any common CAs) and then have his
> public key be entered (for a moderate charge) into a list of public
> keys that is freely accessible to the public at computer terminals of
> all offices of the registration authority. This way, the issue of trust
> on the common CAs (or their equivalents) could be avoided.
I like to quote below a follow-up to my post in comp.misc.
M. K. Shen
---------------------------------------------------------------------
That's how they work in Finland — in theory:
<URL: http://vrk.fi/default.aspx?id=21>
In practice, online identification is done through the Finnish banks'
commercial authentication system.
<URL: https://en.wikipedia.org/wiki/TUPAS>
Marko
[toc] | [prev] | [standalone]
Back to top | Article view | uk.comp.security
csiph-web