Security Basics mailing list archives

Re: Steps to avoid Social Engineering


From: David Roman Esteban <droman () plcendesa com>
Date: Mon, 18 Apr 2005 23:47:34 +0200

We are going to use for this PGP, when we start a maintenance contract
we create a pair of keys that are used for all the communications we
have. If they are security awareness they probably have already
something like this.
This first pair are given by hand to the person who is in charge of the
maintenance contract. If they want some password or "sensitive"
information they have to use encrypted/signed mail.

Best regards
David Roman

    But how could I get this person (or any one in the future) prove
to me that they are the people who are they say they are? Any advice?

Tabs


 



Current thread: