Authentication at toad.com: WTF?

L. Todd Masco cactus at hks.net
Wed Nov 30 12:43:02 PST 1994



Does the idea of having the list software check signatures strike
anybody else as a Bad Idea?  Signatures should be checked locally
by the recipient -- otherwise one might as well ask the sender to
include a statement stating whether or not a message is authentic
and should be believed.  I wouldn't want to see cypherpunks being
used to propogate this false security -- majordomo can no more be
trusted, as an external agent, than a message's sender.






More information about the cypherpunks-legacy mailing list