a few more words about "marginal" tust

I would assign marginal trust to (e.g.) x.509 certificates which are signed by "certificate authorities".    these are passed out like fliers at the fair creating a huge attack surface.     each of us needs only a few of these,  one for the credit union, one for (e.g.) Amazon -- just those sites that we do commercial business with .    Marginal trust might be OK to browse a news site but that's another topic .

getting from marginal trust to full trust requires a SECOND VERIFICATION.     In my view this service should be available at local credit unions, perhaps the DMV office -- places that already need to vet and authenticate identification records.

we need to extend this to the individual as well, while we're at it -- ENIGMAIL should be able to export a public key onto a USB Thumb drive that the use can take to the Credit Union or DMV -- to get it countersigned -- and uploaded to the key server.    this is neede to proceed with PGP security for things like IRS Forms 1040 filings ...    a PGP signature is rather more secure than simply knowing the AGI on line 22 from last year's form -- which is a total kindergarten effort at security .

On 09/20/2015 08:38 AM, Mike Acker wrote:
if you want a third light it could be for the trust level established for the senders key:



not signature: pgp wasn't used
unknown: message is signed but we have no information about the signer
untrusted: messages is signed by a person we recognize but we are not sure if her or she is trustworthy
marginal: marginal trust -- ( I don't like this one )
trusted: full trust -- we are willing to accept authentication and trust level information from this source
ultimate: show for messages signed by local user usually in the SENT box


> > On 09/20/2015 06:51 AM, Patrick Brunschwig wrote: >> On 20.09.15 05:06, Robert J. Hansen wrote: >> > (Forgive the HTML: this is one of the few times where I think it’s >> > worthwhile.  This email uses color to convey information.) >> >> > So, while relaxing with a good stogie, I started mulling over the >> > UX problem of communicating information about encryption status, >> > signatures, validity, and more.  I got nowhere, which is when I >> > decided to burn it all down and start from a clean sheet of paper. > { snip } > > -- > /Mike > > > > _______________________________________________ > enigmail-users mailing list > enigmail-users@enigmail.net > To unsubscribe or make changes to your subscription click here: > https://admin.hostpoint.ch/mailman/listinfo/enigmail-users_enigmail.net

--
/Mike



_______________________________________________
enigmail-users mailing list
enigmail-users@enigmail.net
To unsubscribe or make changes to your subscription click here:
https://admin.hostpoint.ch/mailman/listinfo/enigmail-users_enigmail.net

-- 
/Mike

Attachment: signature.asc
Description: OpenPGP digital signature

_______________________________________________
enigmail-users mailing list
enigmail-users@enigmail.net
To unsubscribe or make changes to your subscription click here:
https://admin.hostpoint.ch/mailman/listinfo/enigmail-users_enigmail.net

Reply via email to