4 ms·
With cryptographic signatures I could at least verify that something stems from the same account that I previously agreed with, but this would require people to
by ls15 4y ago
With cryptographic signatures I could at least verify that something stems from the same account that I previously agreed with, but this would require people to be able to manage their own private keys.
Actually nothing would stop people from signing their own comments today and sometimes it is done.
With e2ee messengers I feel pretty confident that a message comes from the right / real person after I verified their public key.
- exit 4y ago> but this would require people to be able to manage their own private keys a few generations ago social networking would have seemed infeasible because it would require wide spread literacy (along with many other reasons of course). widespread private key management doesn't seem that infeasible to me.
- ls15 4y agoI agree. Key management can be learned (but still has to be learned). I think that cryptocurrency made the biggest impact in this area so far.
- PeterisP 4y agoIt can't provide confidence that the message comes from the right/real person, because even without any breach of secrets (which happen even to competent people/organizations) all that gives you is confidence that the message comes from someone authorized by that right/real person. It could be another person, or it could be data generated by an automated system to which they gave the credentials for whatever reason - historically rich people used personal secretaries for writing all kinds of responses including personal ones ("I'm so grateful for your invitation to visit, let's ..." didn't necessarily mean that the actual person even read your invitation), and if an "artificial secretary" becomes good enough, people will use it in future.
- ls15 4y ago> all that gives you is confidence that the message comes from someone authorized by that right/real person. Which is good enough for many applications, I think. With friends and family, I am pretty confident, that none of them deploy a personal assistant to answer my encrypted messages. As opposed to a messenger where the service provider can inject ads into the messages. How do I know that a person that I speak to IRL is really saying what they think or even really is who they claim to be if I don't know them well? A rest of uncertainty always remains.
- dinvlad 4y agoHow does one really verify someone’s public key in this situation? E.g. a fake account would presumably be able to generate a fake website of themselves that looks at least semi-legit, and use it to post their pubkey. What would give us confidence the key comes from a legit person?