Re: About PGP Signing a File.
- From: Ouattara Oumar Aziz <wattazoum@xxxxxxxxx>
- Date: Tue, 13 Feb 2007 00:27:22 +0100
John L Fjellstad a écrit :
Tony Arnold <tony.arnold@xxxxxxxxxxxxxxxx> writes:The way I understand it is just like Certificates use with SSL. The
It therefore becomes a question of degrees of trust. A document that has
been signed with a key that has also been signed by a number of people
increases that degree of trust, but as you say does not guarantee
authorship. A signature based on a key that has not been signed by
anybody is much less trustworthy.
I don't see how the number of people signing a key makes it more
trustworthy unless you know at least one of the person who signed (and
then you only actually need that one person's signing). A bad guy could
just generate a bunch of new keys to sign the one key you are looking
at.
trust you put on a key depends on the security organization you are in.
So I may have a key signed by the security team of my company, that key
is trustworthy for anyone in that company but outside that company, it's
not valuable at all.
That's why, when I see some people on some mailing list signing there
mail using PGP I just wonder what they want to prove. We have no way to
check the authority behind that key.
--
ubuntu-users mailing list
ubuntu-users@xxxxxxxxxxxxxxxx
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-users
- Follow-Ups:
- Re: About PGP Signing a File.
- From: John L Fjellstad
- Re: About PGP Signing a File.
- From: Duncan Lithgow
- Re: About PGP Signing a File.
- From: Matthew Flaschen
- Re: About PGP Signing a File.
- References:
- About PGP Signing a File.
- From: Joel Bryan Juliano
- Re: About PGP Signing a File.
- From: Matthew Flaschen
- Re: About PGP Signing a File.
- From: John Dangler
- Re: About PGP Signing a File.
- From: Tony Arnold
- Re: About PGP Signing a File.
- From: Jeffrey F. Bloss
- Re: About PGP Signing a File.
- From: Tony Arnold
- Re: About PGP Signing a File.
- From: John L Fjellstad
- About PGP Signing a File.
- Prev by Date: Re: About PGP Signing a File.
- Next by Date: Re: About PGP Signing a File.
- Previous by thread: Re: About PGP Signing a File.
- Next by thread: Re: About PGP Signing a File.
- Index(es):
Relevant Pages
|