Proxy/Representation?

Scott Brickner sjb at universe.digex.net
Fri Dec 29 14:51:13 PST 1995


"David E. Smith" writes:
>That's more of what I was looking for.  I suppose that (I'm still using
>PGP as my example) there could be a shared PGP key, signed by Helen and
>myself, where only the two of us know the passphrase, with a keyid of
>"David Smith <dsmith at midwest.net> on behalf of Helen Jones <helen at devnull.org>"
>or something similar.  The obvious problem is that in sharing the pass
>phrase the security is weakened.  (Paranoid threat model: at some point
>we have to decide on the pass phrase, and we are videotaped/bugged/spied
>upon while this takes place.)

Why bother with the shared key?  You need a message from Helen describing
the powers with which you are invested, signed by her key.  The wonderful
thing about data is that copying it is virtually free.  When you issue an 
order on her behalf, include a copy of the signed PoA, and sign the whole
thing with your key.






More information about the cypherpunks-legacy mailing list