2010/6/29 Wes Kussmaul <w...@authentrus.com>:
> Stanley Lieber wrote:
>>
>> Anywhere legitimate identification is used, legitimate identification can
>> be purchased.
>
> There are imperfect but very good ways to protect against that
> vulnerability. They vary with the needs (and budgets) of relying parties.

I'm pretty sure you can't solve the problem. At the end of the day, it
boils down to client-side security and what a person is willing to
defend with their life. It's perfectly feasible to assume that
identity information in a PKI world can be coerced and stolen as
easily as physical identity information such as drivers licenses and
social security cards. The security always breaks down at the personal
level, and most private individuals aren't willing to die to protect
this information.

But you can do at least as good as these forms of ID. PKI requires
knowledge of some sort of passkey. (I just worry about identification
for people who are not smart enough to pick a good key. Which,
unfortunately, is also most people.

--dho

Reply via email to