[FoRK] Re: identity-based encryption

Tyler Close list at waterken.net
Tue Feb 10 09:12:05 PST 2004

On Tue February 10 2004 12:11 am, Gordon Mohr wrote:
> And yet, as bad as 'phishing' and other confusion-based attacks
> have shown (for one example) SSL and the browser 'lock'/domain
> approach to be, it's still been (1) better than nothing;

Prove it.

You may want to note that many respected security researchers
disagree with your assertion. In particular, Bruce Schneier has

"Digital certificates provide no actual security for electronic
commerce; it's a complete sham."

See the quoted section at:



The union of REST and capability-based security.

