[125293] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

Re: the joy of "enhanced" certs

daemon@ATHENA.MIT.EDU (Dirk-Willem van Gulik)
Wed Jun 4 16:34:15 2008

Date: Wed, 4 Jun 2008 21:30:44 +0100 (BST)
From: Dirk-Willem van Gulik <dirkx@webweaving.org>
To: "Perry E. Metzger" <perry@piermont.com>
cc: cryptography@metzdowd.com
In-Reply-To: <87ve0p6krz.fsf@snark.cb.piermont.com>



On Wed, 4 Jun 2008, Perry E. Metzger wrote:

> I'm thinking of starting a CA that sells "super duper enhanced
> security" certs, where we make the company being certified sign a
> document in which they promise that they're absolutely trustworthy.
> To be really sure, we'll make them fax said document in on genuine
> company letterhead, since no one can forge letterhead.

Sorry - not quite good enough. You lack that key thing to make this 
secure and win the war on them internet terrorists.

You totally missed the fundamental crucial and the totally aspect of your 
Unique Selling Proposition: it _has_ to be very very very expensive. And 
people have to know that it was, indeed, very very expensive.

Dw

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com

home help back first fref pref prev next nref lref last post