Lack of PGP signatures

Rich Graves llurch at networking.stanford.edu
Wed Jul 3 02:08:01 PDT 1996


-----BEGIN PGP SIGNED MESSAGE-----

On Tue, 2 Jul 1996, Derek Atkins wrote:

> Actually, I don't PGP sign my messages because 95% of the time my
> connection to my mail host (the machine on which I read and respond to
> mail) is insecure.  Composing the message, bringing the message to my

"Me too," though I recently created a 512-bit key just for the purpose of
such insecure signing. As long as people understand that that key simply
means "this is either me, or someone who has gone to the trouble of cracking
root here, or someone who spent a couple weeks brute-forcing this key," it's
useful to prevent casual attacks.

Several others are doing the same thing... I know all the NoCeM posters and
most of the newsgroup moderators using PGPMoose have created suuch secondary
keys.

- -rich
 finger or send mail with subject line "send pgp key" if you want 'em

-----BEGIN PGP SIGNATURE-----
Version: 2.6.2

iQBVAwUBMdoJ+JNcNyVVy0jxAQH7fwIAvK/GWCSXtoDyZWIC+rffKjv/VNbQL/J8
nvabWe7DC6NMp6iGmmZCaIkuvD+TON6rEpu3xatyim0R8ILQoSPyfg==
=/wh3
-----END PGP SIGNATURE-----







More information about the cypherpunks-legacy mailing list