Re: not really pgp signing in van

Ted Lemon <Ted.Lemon@nominum.com> Tue, 10 September 2013 18:37 UTC

Return-Path: <Ted.Lemon@nominum.com>
X-Original-To: ietf@ietfa.amsl.com
Delivered-To: ietf@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id F14FA21F9CC6 for <ietf@ietfa.amsl.com>; Tue, 10 Sep 2013 11:37:07 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -106.445
X-Spam-Level:
X-Spam-Status: No, score=-106.445 tagged_above=-999 required=5 tests=[AWL=0.154, BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Kmqj2CFpOnia for <ietf@ietfa.amsl.com>; Tue, 10 Sep 2013 11:36:57 -0700 (PDT)
Received: from exprod7og122.obsmtp.com (exprod7og122.obsmtp.com [64.18.2.22]) by ietfa.amsl.com (Postfix) with ESMTP id 0A15C21F9B66 for <ietf@ietf.org>; Tue, 10 Sep 2013 11:36:56 -0700 (PDT)
Received: from shell-too.nominum.com ([64.89.228.229]) (using TLSv1) by exprod7ob122.postini.com ([64.18.6.12]) with SMTP ID DSNKUi9myEtDvwtzuHhOcwjreLYFlEDIq+mu@postini.com; Tue, 10 Sep 2013 11:36:57 PDT
Received: from archivist.nominum.com (archivist.nominum.com [64.89.228.108]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client CN "*.nominum.com", Issuer "Go Daddy Secure Certification Authority" (verified OK)) by shell-too.nominum.com (Postfix) with ESMTP id A1BC51B8261 for <ietf@ietf.org>; Tue, 10 Sep 2013 11:36:56 -0700 (PDT)
Received: from webmail.nominum.com (cas-02.win.nominum.com [64.89.228.132]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (Client CN "mail.nominum.com", Issuer "Go Daddy Secure Certification Authority" (verified OK)) by archivist.nominum.com (Postfix) with ESMTPS id 99FA119006D; Tue, 10 Sep 2013 11:36:56 -0700 (PDT) (envelope-from Ted.Lemon@nominum.com)
Received: from MBX-02.WIN.NOMINUM.COM ([64.89.228.134]) by CAS-02.WIN.NOMINUM.COM ([64.89.228.132]) with mapi id 14.03.0158.001; Tue, 10 Sep 2013 11:36:56 -0700
From: Ted Lemon <Ted.Lemon@nominum.com>
To: Phillip Hallam-Baker <hallam@gmail.com>
Subject: Re: not really pgp signing in van
Thread-Topic: not really pgp signing in van
Thread-Index: AQHOqpqEB3VH/4NMm0OmqkHjUm9ALJm5aiMAgABaqYD//9WJAIAARlSA///KM4CAAFZ3gIAC1QGAgAAEoYCAAPmWgIAAFPEAgABoNQCAAAGxAIAAFfqAgAAJL4CAADHKgIAAAaIAgAADyACAAARAgIAA+LSAgAAM44CAABEygIAABM6A
Date: Tue, 10 Sep 2013 18:36:55 +0000
Message-ID: <E2ECE63C-D8E4-4A5A-BEA3-295C027D0E71@nominum.com>
References: <20130910010719.33978.qmail@joyce.lan> <8D23D4052ABE7A4490E77B1A012B63077527E234@mbx-01.win.nominum.com> <alpine.BSF.2.00.1309092125360.34090@joyce.lan> <8D23D4052ABE7A4490E77B1A012B63077527E488@mbx-01.win.nominum.com> <CAMm+LwhZ9OKesZW+kFct5Gps6_JBzcNUUBQ-y5J21zMcxmL6EQ@mail.gmail.com> <241D1DD6-C096-49D6-A05B-33638846BF15@nominum.com> <CAMm+LwhhUzDX=AaJXSCkqJofHQ9ZiN11GmCw-reO0OPmNC4fyA@mail.gmail.com>
In-Reply-To: <CAMm+LwhhUzDX=AaJXSCkqJofHQ9ZiN11GmCw-reO0OPmNC4fyA@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [192.168.1.10]
Content-Type: text/plain; charset="iso-8859-1"
Content-ID: <0DFEF85378E40D4FA63F69A4493FBBA3@nominum.com>
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Cc: John R Levine <johnl@taugh.com>, "<ietf@ietf.org>" <ietf@ietf.org>
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ietf>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 10 Sep 2013 18:37:08 -0000

On Sep 10, 2013, at 2:19 PM, Phillip Hallam-Baker <hallam@gmail.com> wrote:
> You go to a Web page that has the HTML or Javascript control for generating a keypair. But the keypair is generated on the end user's computer.

So I run Javascript provided by Comodo to generate the key pair.   This means that my security depends on my willingness and ability to read possibly obfuscated Javascript to make sure that it only uploads the public half of the key pair.