If your key is in my database prior to you requesting peerage (it was),
it indicates to me that it was not generated strictly for the purpose of
this communication.

If your identity ever comes in to question, I can remove you from the
membership list until such time as I can request a trusted third party
audit your operations.

On Sun, 2010-08-22 at 21:10 +0200, Christoph Anton Mitterer wrote:

> On Sun, 2010-08-22 at 07:43 -0700, C.J. Adams-Collier KF7BMP wrote:
> > Generating a signed message is as simple as this:
> Yes,... but it gives you _no proof at all_ .
> 
> Even if _I_ would sign this. Anybody in between us two can simply catch
> that message (and yours), take another key, and do the same signing.
> You'd never notice that.
> Therefore, one needs personal meetings in order to do keysigning.
> 
> See wikipedia for man-in-the-middle-attacks.
> 
> 
> 
> Cheers,
> Chris.
> 


Attachment: signature.asc
Description: This is a digitally signed message part

_______________________________________________
Sks-devel mailing list
Sks-devel@nongnu.org
http://lists.nongnu.org/mailman/listinfo/sks-devel

Reply via email to