Full Disclosure mailing list archives

Re: PGP vs. certificate from Verisign


From: Shawn McMahon <smcmahon () eiv com>
Date: Mon, 12 May 2003 12:52:33 -0400

On Mon, May 12, 2003 at 01:21:31PM +0200, yossarian said:

defences - who do you trust? Maybe the CA has good policies, and maybe the
auditing by some accounting firm (KPMG, CGEY, etc.) is good, but all you can
do here is believe or not believe them - the reports are just paper. There

Since KPMG once accidentally sent me an email that was evidently
intended to be a confidential "on background" response to a reporter
from The Economist, I'm not inclined to assign them infinite trust.

(eiv.com and eiu.com are awfully close, and at the time I had all mail
for unknown users going to me instead of being bounced.  The daily flood
of stuff for Rush Limbaugh cured me of that.)


-- 
Shawn McMahon     | Let every nation know, whether it wishes us well or ill,
EIV Consulting    | that we shall pay any price, bear any burden, meet any
UNIX and Linux    | hardship, support any friend, oppose any foe, to assure
http://www.eiv.com| the survival and the success of liberty. - JFK

Attachment: _bin
Description:


Current thread: