[13470] in cryptography@c2.net mail archive
Re: Maybe It's Snake Oil All the Way Down
daemon@ATHENA.MIT.EDU (James A. Donald)
Fri Jun  6 14:50:35 2003
X-Original-To: cryptography@metzdowd.com
X-Original-To: cryptography@metzdowd.com
Date: Wed, 04 Jun 2003 19:09:31 -0700
From: "James A. Donald" <jamesd@echeque.com>
In-reply-to: <kjd6ht8l5j.fsf@romeo.rtfm.com>
To: Eric Rescorla <ekr@rtfm.com>
Cc: pgut001@cs.auckland.ac.nz (Peter Gutmann),
	bill.stewart@pobox.com, cryptography@metzdowd.com,
	cypherpunks@lne.com, rsalz@datapower.com, sguthery@mobile-mind.com
    --
James A. Donald
> > > > Or to say the same thing in different words -- why 
> > > > can't HTTPS be more like SSH?    Why are we seeing a 
> > > > snow storm of scam mails trying to get us to login to 
> > > > e-g0ld.com?
Eric Rescorla
> > > Because HTTPS is designed to let you talk to people 
> > > you've never talked before, which is an inherently harder 
> > > problem than allowing you to talk to people you have.
James A. Donald:
> > In attempting to solve the hard problem, it fails to make 
> > provision for solving the easy problem.
Eric Rescorla
> Nonsense. One can simply cache the certificate, exactly as 
> one does with SSH. In fact, Mozilla at least does exactly 
> this if you tell it to. The reason that this is uncommon is 
> because the environments where HTTPS is used are generally 
> spontaneous and therefore certificate caching is less useful.
Certificate caching is not the problem that needs solving.  The 
problem is all this spam attempting to fool people into logging 
in to fake BofA websites and fake e-gold websites, to steal 
their passwords or credit card numbers 
    --digsig
         James A. Donald
     6YeGpsZR+nOTh/cGwvITnSR3TdzclVpR0+pr3YYQdkG
     /UOLlqGTeq9SAB5W/aJJuwULFBNMCVzKJnIRlhES
     48E3I0Yo+68OTvTwztxirTXc41yFVicJtskuBB/dU
---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com