4 ms·
If there is a right to be forgotten, perhaps there is a right to deny authorship as well?
by wilwade 10y ago
If there is a right to be forgotten, perhaps there is a right to deny authorship as well?
- alanh 10y agoI of course want to reject this out of hand, but it's better to be thoughtful. PRO: - Enable changing of minds without being shackled to former identity? CON: - Now a statement that is incontestably true can be ILLEGAL and a LIABILITY if not immediately retracted - Historical revisionism - Memory hole
- dredmorbius 10y agoRepudiability is a feature of some systems, difficult with others. PGP-signed messages, for example, are not only authenticated and of proven integrity, but they are nonrepudiable, at least cryptographically. (Bad key management or other factors might affect any of these, but generally these are characteristics of the system.) Designing a system which does allow for encryption and authentication but also provides for repudiability would be interesting.
- Natanael_L 10y agoPerfect forward secrecy. Signal's 3DH key exchange does it. The authentication output is only meaningful to the original conversation participants, because the only discernable difference between a real and a fake authentication even with access to all user keys and ciphertext is provenance - you know this output originated from a direct response to your cryptographic challenge, but nobody else can be sure you didn't just compose it yourself. (Only the key-holders in a conversation between the "authenticatee" and challenger can generate valid looking answers for their specific pair of keys - either mutually between each other, or all by themselves in order to achieve repudiation)
- dredmorbius 10y agoClarifying: 3DH only assures authentication to the original participants itself. However if a message payload itself consisted of, say, a PGP-signed message, then that could be authenticated independently (either on receipt, or if/when the public key was disclosed).