Stories
Slash Boxes
Comments

News for nerds, stuff that matters

Congress Moving On E-Signatures

Posted by CmdrTaco on Fri Jun 09, 2000 01:26 PM
from the sign-with-a-0101011101010101010101000010 dept.
Silas writes: "Well folks, Congress is moving along with attempts to make digital signatures legally binding for online transactions, public and private." Many pros and cons if this goes through, but I'm definitely looking forward to reducing my mail.
This discussion has been archived. No new comments can be posted.
Congress Moving on E-Signatures | Log In/Create an Account | Top | 158 comments (Spill at 50!) | Index Only | Search Discussion
Display Options Threshold:
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
(1) | 2 | 3
  • History in the making ... by codefool (Score:1) Friday June 09 2000, @08:43AM
  • Wait a sec.. (Score:3)

    by citizenc (60589) <cary@@@glidedesign...ca> on Friday June 09 2000, @08:44AM (#1013397) Journal
    The article tells us that the senate is moving for digital signatures that are as legally binding as a pen and paper signature. Does that mean that current internet documents that are "digitally signed + legally binding" are, in fact, NOT legally binding? (Case in point: the Napster [napster.com]-getting-unbanned-by-Metallica declaration?)

    Does this mean that, in it's current state, a legally-binding, digitally-signed document does NOT exist?


    .- CitizenC (User Info [slashdot.org])
  • Re:Are digital signatures that authentic? by gfecyk (Score:1) Friday June 09 2000, @08:44AM
  • Twins and DNA by Bryan Andersen (Score:1) Sunday June 11 2000, @09:25AM
  • Re:SPELLING IT OUT FOR THE SIMPLE MINDED 0000 by TinMan00 (Score:1) Wednesday June 14 2000, @06:26PM
  • SPELLING IT OUT FOR THE SIMPLE MINDED 0000 by TinMan00 (Score:1) Friday June 09 2000, @11:00AM
  • Re:This *is* a good idea by CConkle (Score:1) Friday June 09 2000, @11:02AM
  • Re:Oh Joy by Steeltoe (Score:1) Friday June 09 2000, @11:06AM
  • Re:My rot13 beats your scrawl by T-Ranger (Score:2) Friday June 09 2000, @11:06AM
  • by Greyfox (87712) on Friday June 09 2000, @11:07AM (#1013405) Homepage
    The Post Office would be perfect for this job. You've got a branch office in every city in the USA (Minimum requirement to be a city anywhere in the south is that there be a Post Office and a McDonalds.) Why not implement a scheme like this:

    1) Create a key in PGP or GPG.

    2) Put the public key on a floppy and take it down to the Post office.

    3) Show them your passport or your drivers license and Social Security card and give them the floppy and $5.

    4) They put it on their LDAP keyserver, accessable at ldap.usps.gov.

    5) Anyone wanting to authenticate your identity would check there.

    You could offer some really neat features in a system like this, such as the possibility of creating arbitrairly anonymous keys for use in handle based fora or Hotmail accounts. If your key is compromised, you'd just go to the Post Office and issue a cancel certificate. Ideally there'd be limitations of liability similar to what you get with credit cards if you issue a cancel certificate in a timely fashion after discovering your keys have been potentially compromised. Especially since most computers on the net are insecure.

  • Re:Verisign and NSI by Jon_E (Score:1) Friday June 09 2000, @11:12AM
  • Re:This *is* a good idea by Somnus (Score:1) Friday June 09 2000, @11:12AM
  • Re:Forging signatures by geekoid (Score:1) Friday June 09 2000, @11:15AM
  • Re:Issues of security by geekoid (Score:1) Friday June 09 2000, @11:20AM
  • Re:Oh Joy by (void*) (Score:2) Friday June 09 2000, @08:45AM
  • Re:Not until we have secure operating systems by TheNecromancer (Score:1) Friday June 09 2000, @08:46AM
  • Re:Oh Joy by tringstad (Score:2) Friday June 09 2000, @08:46AM
  • Re:Legal yes, but is is feasable? by / (Score:2) Friday June 09 2000, @08:47AM
  • Re:Hehehe... by GeZ117 (Score:1) Friday June 09 2000, @08:48AM
  • Re:Great, I Can See It Now... by gfecyk (Score:1) Friday June 09 2000, @08:48AM
  • Re:Not until we have secure operating systems by mizhi (Score:1) Friday June 09 2000, @08:49AM
  • Re:Wait a sec.. by (void*) (Score:1) Friday June 09 2000, @08:49AM
  • Making digital signatures legally binding scares the shit out of me.

    Keep in mind that, even with current 'legaly binding' signatures, you can potentialy always go to court and say "I diddnt sign that".

    Because of this, important contracts require a witness (who could also potentialy say "I diddnt see him sign that, and someone forged my name too!"), and realy important contracts need to be signed and notarized by something like a Notary Public, a Comissioner of Oathes, or even a judge.

    When I say "require" I dont mean "legaly necessary" but "expected" and/or "required" by the other entity involved in the contract to do business with you. IANAL (and working on lay Canadians idea of the law (but this is all prety basic, and basied on English Common Law anyway)) but since there is always the "I diddnt do it" escape, important contracts will always require a third party.

  • Congress is moving? by / (Score:2) Friday June 09 2000, @08:27AM
  • Re:My rot13 beats your scrawl by broter (Score:1) Friday June 09 2000, @11:24AM
  • Re:This *is* a good idea by geekoid (Score:1) Friday June 09 2000, @11:28AM
  • finally! by hexdef6 (Score:1) Friday June 09 2000, @08:27AM
  • Privacy and Online Stalking by Ephro (Score:2) Friday June 09 2000, @11:36AM
  • great by chowda (Score:1) Friday June 09 2000, @08:28AM
  • Idiot. Everybody has root on your system. by roystgnr (Score:2) Friday June 09 2000, @11:41AM
  • Re:This *is* a good idea by titus-g (Score:1) Friday June 09 2000, @11:41AM
  • Re:Wait a sec.. by jonathanclark (Score:2) Friday June 09 2000, @11:47AM
  • by / (33804) on Friday June 09 2000, @08:31AM (#1013428)
    This is one of those areas of the law where all we need is a standard to agree upon, and it doesn't matter too much what exactly that standard is. It's no more oppressive than having governments regulate what gauge the railroads use.
  • Re:Oh Joy by YoungHack (Score:1) Friday June 09 2000, @11:53AM
  • Oh Joy (Score:3)

    by Greyfox (87712) on Friday June 09 2000, @08:31AM (#1013430) Homepage
    Marvel at the snail like pace of the makers of our laws. By the time they've decided on this, we'll have computers fast enough to factor the primes, crack the keys, and render this technology useless.

    Keep up the good work, guys...

  • Re:Issues of security by crypto_creek (Score:1) Friday June 09 2000, @11:59AM
  • CONGRESS MOVES ME...TO TEARS 0000 by TinMan00 (Score:1) Friday June 09 2000, @08:50AM
  • Re:e-sigs for EULAs? by Animol (Score:1) Friday June 09 2000, @08:50AM
  • The Benefits of Digital Signatures by GrayMouser_the_MCSE (Score:1) Friday June 09 2000, @08:51AM
  • Re:Are digital signatures that authentic? by CharlieG (Score:1) Friday June 09 2000, @08:51AM
  • Re:Not until we have secure operating systems by KilobyteKnight (Score:1) Friday June 09 2000, @08:51AM
  • Re:Forging signatures by gfecyk (Score:1) Friday June 09 2000, @08:52AM
  • Re:security by mikpos (Score:1) Friday June 09 2000, @08:53AM
  • Re:Oh Joy by / (Score:2) Friday June 09 2000, @08:53AM
  • Re:Beware signed EULA by Fesh (Score:1) Friday June 09 2000, @12:00PM
  • Click-Wrap Software Licenses by GroundBounce (Score:2) Friday June 09 2000, @12:30PM
  • Congress spanks by Mr804 (Score:1) Friday June 09 2000, @01:02PM
  • Heh. Everybody has root on my system, too. by roystgnr (Score:2) Friday June 09 2000, @01:15PM
  • Re:Bad idea by Lord Kano (Score:1) Friday June 09 2000, @01:31PM
  • Re:biometrics verification systems by Goonie (Score:2) Friday June 09 2000, @01:32PM
  • Certificate Authorities by wls (Score:1) Friday June 09 2000, @08:54AM
  • Issues of security by Langley (Score:1) Friday June 09 2000, @08:55AM
  • Re:Hehehe... by Phroggy (Score:1) Friday June 09 2000, @08:55AM
  • Re:Hehehe... by GeZ117 (Score:1) Friday June 09 2000, @09:00AM
  • Re:SPELLING IT OUT FOR THE SIMPLE MINDED 0000 by Eil (Score:1) Friday June 09 2000, @01:32PM
  • Re:My rot13 beats your scrawl by Eil (Score:2) Friday June 09 2000, @01:42PM
  • Re:e-sigs for EULAs? by Eil (Score:1) Friday June 09 2000, @01:46PM
  • question by Eil (Score:1) Friday June 09 2000, @01:52PM
  • Who determines the signatures? by Twanfox (Score:2) Friday June 09 2000, @02:49PM
  • Re:This *is* a good idea by Twanfox (Score:1) Friday June 09 2000, @02:58PM
  • premature by jetson123 (Score:2) Friday June 09 2000, @03:24PM
  • digital signiture=digital id... mark of the beast? by dbcowboy (Score:1) Friday June 09 2000, @04:36PM
  • Implementation? by qseep (Score:1) Friday June 09 2000, @09:00AM
  • by Somnus (46089) on Friday June 09 2000, @09:00AM (#1013459)
    The increases in efficiency and organization are obvious. However, people are uncomfortable with the supposed security flaws. Some issues which I consider myths:
    • It's all over if a cracker takes my private key! Well, would he/she not still need a passphrase? Just make sure passwords are not cached (this, I admit, is the weak link). Also, you can issue revocation certificates; even if someone else knows the passphrase and has your key, they cannot revoke a revocation certificate.
    • Then the government/corporation/slashdot-satan-for-today will know who I am! Yes, just like with your handwritten signature on any official document, esp. those requiring notarization.
    • My encrypted stuff can be cracked! This takes an immense amount of computer power, and most people are simply not that important. How would you encrypt things at all without computer cryptography? You could be like Richard Feynman, and create codes with your spouse to send encrypted hand-written love letters, but I personally don't have the time or mischievious inclination for that.
    • When I get a signed email from some beautiful celebrity who wants to go out with me, how do I know it's her? That's why all public keys that matter are themselves signed by authentication services, like VeriSign. For personal keys, use these services or maybe the notaries at your local banks will catch on to another money-making opportunity.
    Any disagreements? Am I missing any critical factors?


    *** Proven iconoclast, aspiring epicurean ***
  • What else does this bill provide? by coyote-san (Score:2) Friday June 09 2000, @09:00AM
  • Love Letter contracts. by blueforce (Score:1) Friday June 09 2000, @09:00AM
  • Bad idea by Lord Kano (Score:2) Friday June 09 2000, @09:02AM
  • It'll never happen by Anonymous Coward (Score:1) Friday June 09 2000, @09:03AM
  • Two laws that won't play well together by dsplat (Score:2) Friday June 09 2000, @09:03AM
  • It's a good thing for some of us... by neonsam (Score:2) Friday June 09 2000, @09:04AM
  • My Mother can't read my Signature... by ChiaBen (Score:1) Friday June 09 2000, @09:05AM
  • Re:Certificate Authorities by wls (Score:1) Friday June 09 2000, @09:32AM
  • Let's face it -- 99% of the populace, whether they use Windows (and I'm sure Microsoft will be so kind as to provide a VBScript hook for signing documents or at least publishing private keys, so that virus writers will have a new source of fun), or whether they use Linux (how many desktop-role Linux boxen do you know of that you would consider 100% secure?) is operating insecurely. And that insecurity is going to spell trouble if digital signatures are legally binding, because it opens up a whole new class of forgeries.

    *I* would not consider *any* box, regardless of operating system, platform, etc., to be 100% secure. The main issue with security, aside from the fact that -any- security system can be cracked, has to do with the loose nut behind the mouse. Sorry, but when a security system relies on human intervention, well, humans just aren't very secure. :)

    Yes, a written signature requires human intervention, but there is certainly less vulnerable than password-based security. With digital signatures, anyone who can physically access your private key, which usually means anyone who can get into your box (i.e., type yoru login and password in somewhere), can get to your digital signature. At least with written signatures, your actual human presence is required (excluding of course forgeries which are another matter entirely, that's why for certain legal documents we require them to be notarized or otherwise certified by a third party).

  • Re:This *is* a good idea by Malc (Score:2) Friday June 09 2000, @09:35AM
  • Re:Bad idea by jovlinger (Score:1) Friday June 09 2000, @09:35AM
  • Re:Not until we have secure operating systems by Andy_R (Score:2) Friday June 09 2000, @09:39AM
  • My rot13 beats your scrawl by kwerle (Score:2) Friday June 09 2000, @09:43AM
  • Re:Not until we have secure operating systems by hanway (Score:2) Friday June 09 2000, @04:51PM
  • Re:Wait a sec.. by diypower (Score:1) Friday June 09 2000, @04:56PM
  • by werdna (39029) on Friday June 09 2000, @06:12PM (#1013475) Homepage Journal
    . . . these electronic signature laws are wildly overhyped.

    There is a vast amount of authority (citations available upon request) strongly suggesting that legal formalities for a signed writing (the so-called statute of frauds) are satisfied by an electronic communication annotated or logically associated with a character or characters manifesting an intent to authenticate (legally, not technically).

    In other words, the e-mail:

    "Dear bill.

    I will buy 1000 Model K frobozinators at $600 per frobozinator to be delivered FOB Tampa no later than thursday. Terms: 2% 10/net 30.

    Love, Maria"

    would very likely be enforceable under the common law and the UCC -- even if no encryption or other technical encryption was used. Requirements for signature under the common law are amazingly lax. An X, a fold or tear made in the paper, another's name, a shaving on a cow or even a footprint can constitute a signature.

    The reason for an e-commerce statute is to make any question clear beyond cavil, so to clear the way for lawyers to permit BIG deals to be done without a signed writing. Imagine a few dozen lawyers at a $100M closing. The boss for the buyer smiles and signs "Minnie Mouse," or an "X," citing the case law suggesting that the signature is binding. Maybe so, you would say if you represented the other side, you would nevertheless ask a literate counterpart on the other side to sign the document "properly."

    Its about eggs in baskets. The law should get out of the way of the technology used for signatures, and ratify any actual manifestation of an intent to sign. (electronic documents raise interesting proof issues, but so do traditional physical documents) The risk of misauthentication and the like is a different question to be decided by those who would USE the signature technology, not by those who enforce the agreements into which the parties otherwise clearly entered.
  • Re:Not until we have secure operating systems by The_OSS_Prophet (Score:1) Friday June 09 2000, @06:15PM
  • Can Melissa sign checks? by Googol (Score:1) Friday June 09 2000, @06:16PM
  • Re:Certificate Authorities by PD (Score:1) Friday June 09 2000, @07:40PM
  • Re:Not until we have secure operating systems by alexandn (Score:1) Friday June 09 2000, @07:48PM
  • USPTO-- digital sigatures by canthidefromme (Score:2) Friday June 09 2000, @09:07AM
  • EULAs by Phroggy (Score:1) Friday June 09 2000, @09:07AM
  • Re:Certificate Authorities by PD (Score:1) Friday June 09 2000, @09:07AM
  • survey on digital signature legislation... by an_mo (Score:1) Friday June 09 2000, @09:07AM
  • Re:Oh Joy by jovlinger (Score:1) Friday June 09 2000, @09:11AM
  • by Kaa (21510) on Friday June 09 2000, @09:44AM (#1013485) Homepage
    It's all over if a cracker takes my private key! Well, would he/she not still need a passphrase?

    (1) Most people "for convenience" would store their passphrase (heh, dream on. It's going to be a password, something like 'secret') on their hard drive, right next to the key itself.

    (2) Even if by some stange twist passwords would not be stored on the same hard drive, possession of keys gives you the ability to brute-force passwords off-line. This is highly practical and successful (AFAIK >70% passwords cracked in real-life tests)

    Then the government/corporation/slashdot-satan-for-today will know who I am!

    That's the wrong objection -- mostly they know who you are anyway (a signature from an unknown party is basically worthless). The point is that in the brave new world a record of your actions would be already digitized and stored on a drive/tape somewhere. This makes it os-so-convenient to cross-index and store this stuff for enternity -- just in case, you know...

    My encrypted stuff can be cracked!

    And what does this have to do with the validity of electronic signatures?

    When I get a signed email from some beautiful celebrity who wants to go out with me, how do I know it's her?

    You don't. All a public-key system guarantees is that the entity which signed this particular message has been in possession of a certain private key. There is nothing which associates a number (key) with a person. This, of course, makes the whole thing vastly more complicated than most people imagine. What you call "authentication services" help but a lot of problems still remain.

    Kaa
  • Re:security by bugg (Score:1) Friday June 09 2000, @09:14AM
  • Re:Legal yes, but is is feasable? by technos (Score:2) Friday June 09 2000, @09:44AM
  • Re:Are digital signatures that authentic? by David Price (Score:1) Friday June 09 2000, @09:14AM
  • Re:Law in Italy since 1997 by Fitascious (Score:2) Friday June 09 2000, @09:52AM
  • Re:Are digital signatures that authentic? by jovlinger (Score:1) Friday June 09 2000, @09:14AM
  • um: Re:Not until we have secure operating systems by WolfWithoutAClause (Score:1) Friday June 09 2000, @09:59AM
  • Re:Bad things... by scott@b (Score:1) Friday June 09 2000, @10:01AM
  • Hehehe... by GeZ117 (Score:1) Friday June 09 2000, @08:33AM
  • Great, I Can See It Now... by Coldraven (Score:1) Friday June 09 2000, @08:33AM
  • Please please please by FascDot Killed My Pr (Score:1) Friday June 09 2000, @08:33AM
  • e-sigs for EULAs? by Stephen (Score:1) Friday June 09 2000, @08:34AM
  • Re:Security? Is non-existent! by Kryptonomic (Score:1) Friday June 09 2000, @10:39PM
  • security by sk1tch (Score:1) Friday June 09 2000, @08:34AM
  • Re:Certificate Authorities by B. Samedi (Score:2) Friday June 09 2000, @10:54PM
  • Re:CONGRESS MOVES ME...TO TEARS 0000 by TinMan00 (Score:1) Friday June 09 2000, @11:08PM
  • This could be really nice by _xeno_ (Score:2) Friday June 09 2000, @08:35AM
  • Re:Privacy and Online Stalking by Arcanix (Score:1) Friday June 09 2000, @11:50PM
  • Re:SPELLING IT OUT FOR THE SIMPLE MINDED 0000 by TinMan00 (Score:1) Saturday June 10 2000, @12:29AM
  • Law in Italy since 1997 by an_mo (Score:2) Friday June 09 2000, @08:35AM
  • by Zigg (64962) <matt@zigg.com> on Friday June 09 2000, @08:35AM (#1013505)

    Making digital signatures legally binding scares the shit out of me.

    Let's face it -- 99% of the populace, whether they use Windows (and I'm sure Microsoft will be so kind as to provide a VBScript hook for signing documents or at least publishing private keys, so that virus writers will have a new source of fun), or whether they use Linux (how many desktop-role Linux boxen do you know of that you would consider 100% secure?) is operating insecurely. And that insecurity is going to spell trouble if digital signatures are legally binding, because it opens up a whole new class of forgeries.

    Let's pretend, for a moment, that most programmers are good at implementing cryptography and would never, ever write a program that allowed a key to be compromised by its use. (Hell, I don't trust any programs I write with my private keys.) Even if you've got good cryptography software, where you store your keys is probably going to be compromisable by an enterprising cracker.

    Before anyone even considers making digital signatures legally binding, how about requiring this binding to only take effect if the document was signed by an approved smart card? Make it a parameter of the signature, and make it illegal to write software or create unapproved smart cards that set that parameter.

  • Re:Not until we have secure operating systems by kennylives (Score:1) Saturday June 10 2000, @01:18AM
  • Re:SPELLING IT OUT FOR THE SIMPLE MINDED 0000 by TinMan00 (Score:1) Saturday June 10 2000, @01:29AM
  • Re:SPELLING IT OUT FOR THE SIMPLE MINDED 0000 by jason_aw (Score:1) Saturday June 10 2000, @02:25AM
  • Signatures are not the issue by werdna (Score:2) Saturday June 10 2000, @04:39AM
  • Re:Post office would be perfect for this by werdna (Score:2) Saturday June 10 2000, @04:42AM
  • Electronic signatures are very insecure... by cnvogel (Score:2) Friday June 09 2000, @09:17AM
  • UCITA & Clickwrap & Electronic Signatures by gdyoung (Score:1) Friday June 09 2000, @09:18AM
  • biometrics verification systems by tokengeekgrrl (Score:2) Friday June 09 2000, @09:18AM
  • Re:Not until we have secure operating systems by randombit (Score:1) Friday June 09 2000, @09:19AM
  • Re:Geeks should work without laws by FascDot Killed My Pr (Score:1) Friday June 09 2000, @09:23AM
  • Re:Wait a sec.. by Anonymous Coward (Score:1) Friday June 09 2000, @09:23AM
  • Re: prior signatures by coyote-san (Score:2) Friday June 09 2000, @10:10AM
  • Bad things... by nahtanoj (Score:1) Friday June 09 2000, @09:28AM
  • Re:Bad idea by Johnath (Score:2) Friday June 09 2000, @10:10AM
  • Re:Oh Joy by benwb (Score:1) Friday June 09 2000, @10:11AM
  • Re:Are digital signatures that authentic? by gulped (Score:1) Friday June 09 2000, @10:11AM
  • Re:My Mother can't read my Signature... by Kinjana (Score:1) Friday June 09 2000, @10:12AM
  • Re:Not until we have secure operating systems by orpheus (Score:2) Friday June 09 2000, @10:15AM
  • Legal yes, but is is feasable? by technos (Score:2) Friday June 09 2000, @08:37AM
  • Forging signatures by Kinthelt (Score:1) Friday June 09 2000, @08:37AM
  • Beware signed EULA (Score:4)

    by c_a_moffitt (183159) on Friday June 09 2000, @08:37AM (#1013526)
    Is anybody else afraid that these digital signatures could be applied to future software EULAs giving them actual real power?

    Please digitally sign here in order to install the software that you have already opened and can no longer return. Oh, this means you have already read the 50 pages of draconian fine print with your lawyer present.

    Craig

  • If they know what they're doing... by fredbevins (Score:1) Friday June 09 2000, @08:38AM
  • Re:Geeks should work without laws by FascDot Killed My Pr (Score:2) Friday June 09 2000, @08:38AM
  • Re:Hehehe... by _xeno_ (Score:1) Friday June 09 2000, @08:39AM
  • Hum... by GeZ117 (Score:1) Friday June 09 2000, @08:40AM
  • Are digital signatures that authentic? by (void*) (Score:2) Friday June 09 2000, @08:40AM
  • Re:This *is* a good idea by iabervon (Score:1) Saturday June 10 2000, @06:32AM
  • RSA-38 has never been considered secure. by rjh (Score:2) Saturday June 10 2000, @06:58AM
  • Re:Beware signed EULA by jamesn9798 (Score:1) Saturday June 10 2000, @09:17AM
  • Well done! by DoronRajwan (Score:1) Saturday June 10 2000, @11:38AM
  • Re:Security? Is non-existent! by BenByer (Score:1) Friday June 09 2000, @10:15AM
  • What exactly is a "WUT "? by _Wrath_ (Score:1) Friday June 09 2000, @10:16AM
  • Re:Are digital signatures that authentic? by WolfWithoutAClause (Score:1) Friday June 09 2000, @10:16AM
  • Re:Electronic signatures are very insecure... by scott@b (Score:1) Friday June 09 2000, @10:17AM
  • Re:Security? Is non-existent! by BenByer (Score:1) Saturday June 10 2000, @03:16PM
  • Re:Privacy and Online Stalking by Ephro (Score:2) Saturday June 10 2000, @04:32PM
  • by jcostom (14735) on Friday June 09 2000, @10:22AM (#1013542) Homepage
    Bear in mind, I'm a former VeriSign employee. I didn't work in the PKI side of the house. I was the technical manager for the NE region in the security services division (formerly SecureIT).

    When you listen to PKI companies give their shtick about how wonderful PKI is and how it will save the universe, apply some simple common sense.

    1. Who holds your private key (besides you)? - If you use the VeriSign solution for digital certs (the one where they manage the CA for you), in addition to your users having their keys, so does VeriSign. If you roll your own, your users have their private keys, and probably also the administrator who gen'd it for them (for when the user accidently deletes their keys). How will users store their private keys? On their hard drives? Poor security, easily obtained by a ruthless 3rd party. Floppy? Unreliable medium, more susceptible to theft. Smart Card? Susceptible to theft.

    2. Remember when 128 bit keys was way too big to be factored? I do, and I'm all of 28 years old. Even with using 1024 bit keys, it's only a matter of a couple of years before many keys are useless. For the uninitiated, I've got your public key, and can find the prime factorization for a number that is your public key and your private key (for all intents and purposes, it's a bit more involved, but not THAT much more). If I compromise your private key in this way, you have no knowledge that I've done so (unless I'm a big moron about doing it), and I can freely digitally sign documents as if I were you. The signatures will even validate properly. Fun, huh? Maybe I'll buy some stuff over the net with your keys, and have it drop-shipped to a Mailboxes, etc. or some other such place.

    3. Complexity of the system - I don't know about everyone else, but my mother barely grasps the concepts behind sending email and pulling up a web page. How's she ever going to understand the how and why it's not only safe, but legally binding to use PKI technologies to enter into agreements?
    --

  • Re:Not until we have secure operating systems by Ed Avis (Score:2) Saturday June 10 2000, @11:41PM
  • Re:biometrics verification systems by BenByer (Score:1) Friday June 09 2000, @10:26AM
  • a modest proposal by grrrreg (Score:1) Friday June 09 2000, @10:30AM
  • Re:Geeks should work without laws by Todd Boyle (Score:1) Sunday June 11 2000, @08:03AM
  • Re:Oh Joy by tringstad (Score:1) Friday June 09 2000, @10:31AM
  • Re:My rot13 beats your scrawl by Greyfox (Score:2) Friday June 09 2000, @10:55AM
  • by Miou (115025) on Friday June 09 2000, @08:40AM (#1013549)
    What I don't even see mentioned in the article is the verification process used to insure that the keyholder really is the person they claim to be.

    Anyone can create a key claiming to be someone else - the only way you know that the key really does represent the person it claims to be representing is if: a) the person gave you their public key in person, or b) there is an authority that "signs" the key, confirming that it is in fact from that person.

    Now, this is really no differant than the way things are today - anyone can sign a check as "Bill Gates," this is why Notaries exist. Are we going to extend the Notary system to have them sign public keys as well?

  • by eries (71365) <slashdot-eric.sneakemail@com> on Friday June 09 2000, @08:40AM (#1013550) Homepage
    let's not be too negative yet. I still think could be a really interesting step, as long as appropriate measures are made to confirm the digital signature for important transactions. Just like a bank won't give you a big loan without you coming in in person so they can verify that you're real. It would be nice if we could get a setup like current credit cards - not 100% secure but if your signature gets compromised you have pretty easy recourse to have the damage undone.

    Is that feasible? Technically? Legally?

    Want to work at Transmeta? MicronPC? Hedgefund.net? AT&T?

  • Woohoo! by Zen (Score:1) Friday June 09 2000, @08:41AM
  • How secure have signatures been lately anyhow? by ParticleGirl (Score:1) Friday June 09 2000, @08:42AM
  • Re:Oh Joy by pete-classic (Score:1) Friday June 09 2000, @08:43AM
(1) | 2 | 3