Re: Revoking Old Lost Keys

At 9:10 AM 1/6/96, James Black wrote:
Hello,
On Fri, 5 Jan 1996, Bruce Baugh wrote:
The problem is this: how can one spread the word that an old key is no longer to be used when one no longer has the pass phrase, and cannot therefore create a revocation certificate?
If there is someone that you trust (or several people), just make a revocation certificate and possibly cut it into pieces, and just let those know when to send it out, so that you don't have to rely on a faulty memory, and by having it in several hands they can't just send it out, as they don't know the other people. Just a thought.
If one can safely and securely store a revocation certificate for later use, why not just store the much shorter passphrase? --Tim May We got computers, we're tapping phone lines, we know that that ain't allowed. ---------:---------:---------:---------:---------:---------:---------:---- Timothy C. May | Crypto Anarchy: encryption, digital money, tcmay@got.net 408-728-0152 | anonymous networks, digital pseudonyms, zero W.A.S.T.E.: Corralitos, CA | knowledge, reputations, information markets, Higher Power: 2^756839 - 1 | black markets, collapse of governments. "National borders aren't even speed bumps on the information superhighway."

-----BEGIN PGP SIGNED MESSAGE----- Tim May writes:
If one can safely and securely store a revocation certificate for later use, why not just store the much shorter passphrase?
Well, you're dealing with very different threats in the two cases AFAICS. With your passphrase and private key, someone can forge your signature, read your encrypted incoming mail, etc. With your revocation certificate and private key, about all they can do is revoke your key and force you to create a new one. I certainly find the latter prospect much less alarming -- by far the lesser of two evils. Heck, it's good to update keys periodically, so they might even be doing me a favor of sorts ;) Futplex <futplex@pseudonym.com> -----BEGIN PGP SIGNATURE----- Version: 2.6.2 iQEVAwUBMO65WSnaAKQPVHDZAQEIngf+OnXNLpkc4MlE+F0O24lCgso29k0cYRiW jOHKJJfl9ryfaM/WT8eyRLIbWhO7A2qMGSF9nlRUCuhLBgQuX6tmboTwDPW3RPzq jKbZ6LO615w0xPhZpDQO/B963sF0UOcIc0v49k1Ua6biUeEQ/0luYn7nQPD9RVDV pb0qkk201qgVDkXXxPR+hN/HXstI0mc2+HjQjAhHiIOLyiMN3aPwGDH1XmHP5UiE TVw+M9cAqyC863KMg+WEkIGXvdwLJ2or6QQ07i50Zwl905mSFd9+nHVx5HLbkKFa UZvwU46zZXx069MIKHLFY2hX1ZqgR5eGGHUa6bZbMkeIjSl50IzILA== =ssJd -----END PGP SIGNATURE-----
participants (2)
-
futplex@pseudonym.com
-
tcmay@got.net