Slashdot Mirror


User: smu2004

smu2004's activity in the archive.

Stories
0
Comments
1
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 1

  1. Only central. dirs can bring crypto to the masses on Ciphire, A Transparent, Easy PGP Alternative · · Score: 1

    Due to the nature of the Fingerprint List (FPL), which is a really unique feature of Ciphire Mail, that won't be possible. Or rather: It would be possible but won't go unnoticed. As soon as Alice, Bob or any other user of Ciphire Mail sends an email, the client automatically checks the current FPL and would notice that the database has been compromised.

    As for the lookup of certificates: First, the client caches lookup results for three days, so Ciphire wouldn't see how many mails Alice sent to Bob. Second, the lookup is done with a semi-anonymous token, not with the full certificate of Alice, so actually, Ciphire can't really tell wether Alice made the lookup or someone else who happens to have the same lookup token as Alice. Third, there will be lookup servers (proxies) run by external entities. In fact, the first external proxy is already set up and will probably announced soon. It's going to be run by an entity which I assume is highly trusted among geeks readers of /. (especially german ones). And only the proxy could be able to associate lookups to email addresses with an above 0 probability.

    cu,
    sven