Re: pgp signing in van

Ted Lemon <ted.lemon@nominum.com> Sat, 07 September 2013 02:25 UTC

Return-Path: <Ted.Lemon@nominum.com>
X-Original-To: ietf@ietfa.amsl.com
Delivered-To: ietf@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6E80621F9C6F for <ietf@ietfa.amsl.com>; Fri, 6 Sep 2013 19:25:29 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -106.29
X-Spam-Level:
X-Spam-Status: No, score=-106.29 tagged_above=-999 required=5 tests=[AWL=-0.291, BAYES_00=-2.599, J_CHICKENPOX_21=0.6, RCVD_IN_DNSWL_MED=-4, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 1EF8UMaDMo0I for <ietf@ietfa.amsl.com>; Fri, 6 Sep 2013 19:25:22 -0700 (PDT)
Received: from exprod7og129.obsmtp.com (exprod7og129.obsmtp.com [64.18.2.122]) by ietfa.amsl.com (Postfix) with ESMTP id 929CC21F9C60 for <ietf@ietf.org>; Fri, 6 Sep 2013 19:25:02 -0700 (PDT)
Received: from shell-too.nominum.com ([64.89.228.229]) (using TLSv1) by exprod7ob129.postini.com ([64.18.6.12]) with SMTP ID DSNKUiqOfssbdpJ2+myFl4NTKVoRSRCz8qCn@postini.com; Fri, 06 Sep 2013 19:25:02 PDT
Received: from archivist.nominum.com (archivist.nominum.com [64.89.228.108]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client CN "*.nominum.com", Issuer "Go Daddy Secure Certification Authority" (verified OK)) by shell-too.nominum.com (Postfix) with ESMTP id 455061B8184 for <ietf@ietf.org>; Fri, 6 Sep 2013 19:25:02 -0700 (PDT)
Received: from webmail.nominum.com (cas-01.win.nominum.com [64.89.228.131]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (Client CN "mail.nominum.com", Issuer "Go Daddy Secure Certification Authority" (verified OK)) by archivist.nominum.com (Postfix) with ESMTPS id 3C24419007A; Fri, 6 Sep 2013 19:25:02 -0700 (PDT) (envelope-from Ted.Lemon@nominum.com)
Received: from [10.0.10.40] (192.168.1.10) by CAS-01.WIN.NOMINUM.COM (192.168.1.100) with Microsoft SMTP Server (TLS) id 14.2.318.4; Fri, 6 Sep 2013 19:24:56 -0700
Content-Type: text/plain; charset="iso-8859-1"
MIME-Version: 1.0 (Mac OS X Mail 7.0 \(1805\))
Subject: Re: pgp signing in van
From: Ted Lemon <ted.lemon@nominum.com>
In-Reply-To: <CAPv4CP_ySqyEa57jUocVxX6M6DYef=DDdoB+XwmDMt5F9eGn1A@mail.gmail.com>
Date: Fri, 06 Sep 2013 22:24:52 -0400
Content-Transfer-Encoding: quoted-printable
Message-ID: <A6B01C4B-B59A-49FD-9524-D49F85750BF7@nominum.com>
References: <m2zjrq22wp.wl%randy@psg.com> <2309.1378487864@sandelman.ca> <522A5A45.7020208@isi.edu> <CA2A6416-7168-480A-8CE1-FB1EB6290C77@nominum.com> <522A71A5.6030808@gmail.com> <6DE840CA-2F3D-4AE5-B86A-90B39E07A35F@nominum.com> <CAPv4CP_ySqyEa57jUocVxX6M6DYef=DDdoB+XwmDMt5F9eGn1A@mail.gmail.com>
To: Scott Brim <scott.brim@gmail.com>
X-Mailer: Apple Mail (2.1805)
X-Originating-IP: [192.168.1.10]
Cc: IETF discussion list <ietf@ietf.org>
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ietf>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 07 Sep 2013 02:25:30 -0000

On Sep 6, 2013, at 10:18 PM, Scott Brim <scott.brim@gmail.com> wrote:
> Dilution of trust is a problem with PGP. "I know this person as X" is way too lax if you want the system to scale.

It's naive to think that keys are any more trustworthy than this, because any signature's trustworthiness is only as good as the trustworthiness of the individual who decides to sign it.   If you trust a key signed by someone you don't know, but who someone you know trusts, just how trustworthy is that?

The web of trust scales just fine if you don't expect too much from it.   If you expect the kind of trustworthiness you seem to be talking about, then it's pretty much useless, because you can really only trust yourself to that degree.

I don't know if this is the sort of absolutism Ted Ts'o was talking about, but I think it is.   Sometimes best is the enemy of good enough, and this is particularly true when best is actually not achievable anyway.