Re: the introduction problem, was Email and reputation (was Re: Service outages planned for April 25)

Masataka Ohta <mohta@necom830.hpcl.titech.ac.jp> Sun, 15 May 2022 05:49 UTC

Return-Path: <mohta@necom830.hpcl.titech.ac.jp>
X-Original-To: ietf@ietfa.amsl.com
Delivered-To: ietf@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6F0A6C1D3C48 for <ietf@ietfa.amsl.com>; Sat, 14 May 2022 22:49:28 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.755
X-Spam-Level:
X-Spam-Status: No, score=-3.755 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, NICE_REPLY_A=-1.857, SPF_HELO_NONE=0.001, SPF_NONE=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id xIqyL52KFxMq for <ietf@ietfa.amsl.com>; Sat, 14 May 2022 22:49:26 -0700 (PDT)
Received: from necom830.hpcl.titech.ac.jp (necom830.hpcl.titech.ac.jp [131.112.32.132]) by ietfa.amsl.com (Postfix) with SMTP id DAEA7C1D3C47 for <ietf@ietf.org>; Sat, 14 May 2022 22:49:23 -0700 (PDT)
Received: (qmail 53819 invoked from network); 15 May 2022 05:44:33 -0000
Received: from necom830.hpcl.titech.ac.jp (HELO ?127.0.0.1?) (131.112.32.132) by necom830.hpcl.titech.ac.jp with SMTP; 15 May 2022 05:44:33 -0000
Message-ID: <06ec8063-a6e0-3bde-3545-e9172ed97336@necom830.hpcl.titech.ac.jp>
Date: Sun, 15 May 2022 14:49:20 +0900
MIME-Version: 1.0
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:91.0) Gecko/20100101 Thunderbird/91.9.0
Subject: Re: the introduction problem, was Email and reputation (was Re: Service outages planned for April 25)
Content-Language: en-US
To: ietf@ietf.org
References: <20220514171447.23A3840334EA@ary.qy>
From: Masataka Ohta <mohta@necom830.hpcl.titech.ac.jp>
In-Reply-To: <20220514171447.23A3840334EA@ary.qy>
Content-Type: text/plain; charset="UTF-8"; format="flowed"
Content-Transfer-Encoding: 7bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/ietf/mfJ-zLIcfZSuLMAemSTS7E-bkv0>
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.34
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ietf/>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 15 May 2022 05:49:28 -0000

John Levine wrote:

> That's exactly web of trust, and we have seen why that doesn't scale,

Cryptographic security requires key sharing directly between
the first and the second parties without any intermediate
intelligent entities as third parties and just can not scale.

> because your contacts' preferences aren't yours.
It explains why PKI is not cryptographically secure.

Your CA is not yours but merely an untrustworthy third party.

 > ("Gee, he seemed so
 > nice and it would have been rude to refuse.")

An or all the employees of a CA may be compromised
that way.

							Masataka Ohta