Re: Sad situation!!!

Bill Sommerfeld <sommerfeld@orchard.medford.ma.us> Thu, 03 October 1996 12:10 UTC

Received: from cnri by ietf.org id aa01373; 3 Oct 96 8:10 EDT
Received: from [192.94.214.96] by CNRI.Reston.VA.US id aa07893; 3 Oct 96 8:10 EDT
Received: from neptune.tis.com by neptune.TIS.COM id aa02910; 3 Oct 96 7:43 EDT
To: Peter Williams <peter@verisign.com>
Cc: "pem-dev@tis.com" <pem-dev@tis.com>, "'Frederik H. Andersen'" <fha@dde.dk>
Subject: Re: Sad situation!!!
In-Reply-To: Your message of "Wed, 2 Oct 1996 11:19:41 -0700 ." <9610021443.aa21905@neptune.TIS.COM>
Date: Thu, 03 Oct 1996 00:00:20 -0400
From: Bill Sommerfeld <sommerfeld@orchard.medford.ma.us>
MMDF-Warning: Unable to confirm address in preceding line at neptune.TIS.COM
MMDF-Warning: Unable to confirm address in preceding line at neptune.TIS.COM
Sender: pem-dev-approval@neptune.tis.com
Precedence: bulk
Message-ID: <9610030734.aa02878@neptune.TIS.COM>

   Its not believable, given the personal credibilty problems which
   would result, that a PGP trademarked product will ever support key
   recovery

Actually, I thought Viacrypt's PGP 4.0 business edition implemented a
form of key recovery.

   (The above assumes, corporates do in fact demand key recovery, to control
   access to their own property.)

Right, but the business need is for key recovery for documents held
over the long term -- to recover from "lost" keys and "lost"
employees; I don't think there's a business need for key recovery for
real-time communications ... if the business owns one or both ends,
they can tap there; if they don't own both ends, they're probably a
network service provider and they don't really *want* to know what
their customers are doing with their network.

Government interest in key recovery seems primarily focussed towards
wiretapping conversations in real time.

				- Bill