Update on mail bombing threats--not so funny

So in order to post to nanog you would have to have your PGP
key signed by NANOG or the list operator or another entity trusted
by all. How do you establish trust for that signing?

Having a key-signing party at the upcoming NANOG is a good
place to start.

The Usenix key signing is a good model for techie types, but
we are the minority. How would the great unwashed have their
keys signed? Besides, I like being able to post without having to
attend a NANOG meeting though I could live with the restriction.

Strong crypto for the masses!

For what it's worth, the same model holds true for meetings of
the IETF; Ted Tso has been organizing key-signing parties that
are held one evening during IETF week.

- - paul

-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: 2.6.2

mQCNAiuk0/8AAAEEALqlLc+x9lmgiJCRSpu/aPhQdi0hMjwiGlN2B/GJQqgZPhTb
pR+u5/blGogqT+WwcXZ2XfEdIV19FrJY4BXGGn4+4TjdVN3XuuCHuueoygBAmOQD
IloU6SJuDqJa0kFA5X/i/1ELn86I5+8A4Hx88FiYJIVUBR6SApRLcZSdHMBNAAUR
tCJQYXVsIEZlcmd1c29uIDxwZmVyZ3Vzb0BjaXNjby5jb20+
=p8D4
-----END PGP PUBLIC KEY BLOCK-----

>So in order to post to nanog you would have to have your PGP
>key signed by NANOG or the list operator or another entity trusted

Having a key-signing party at the upcoming NANOG is a good
place to start.

No doubt, but it doesn't address the problem that started this
thread. Yes, spreading the use of PGP is a good thing, but I
don't see it as a tool to fight spam or, more importantly, spam
terrorisim. Not in the near term anyway.

Strong crypto for the masses!

But of course :slight_smile: If we can deploy it widely enough. We encourage
all of our clients to use PGP.

For what it's worth, the same model holds true for meetings of
the IETF; Ted Tso has been organizing key-signing parties that
are held one evening during IETF week.

The point I was trying to make was that most on-line groups don't have
real life, face to face meetings. They can't implement the key signing
model.

Maybe requiring signed posts wouldn't be that bad of an idea. While
the policy wouldn't solve anything right now it could serve as an example.

Hmm

Dan
- --
Dan Busarow 714 443 4172
DPC Systems dan@dpcsys.com
Dana Point, California 83 09 EF 59 E0 11 89 B4 8D 09 DB FD E1 DD 0C 82