On mySimon: Egg & Muffin 2-Slice Toaster
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 1 of 21:
Next »
Activation energy vs. activation errors
I've used, designed and maintained PGP extensively from the early days where no part was user friendly up to the current day where post-activation use is very slick. I?ve also used, designed and maintained PKI?s for years. In both cases for Fortune 1000 companies.
In my opinion, for the user, (let?s assume that the infrastructure was designed and installed by experts), PGP requires slightly more activation energy than PKI. In both cases, performing signature and encryption requires that both users have been provisioned with key pairs. The cryptography involved is basically the same. Both products use the appropriate keys to verify the other party and securely exchange a secret (symmetric) key. Back to activation? at this point, let?s assume that the PGP user publishes his public key to a PGP key server and the PKI user publishes his key (with X-509 certificate to an LDAP directory). Now, if Alice and Bob have both done this, when they want to email each other for the first time, once can query the appropriate server for the other?s public key and associate it with the others contact record in their email app. Whether Alice and Bob were using PKI or PGP, the activation energy has been the same to this point. But wait? the PKI users are done, but the PGP user?s still have more work to do.
Here?s where PKI wins out both in security and ease of activation. With PKI, the hierarchy of trust is done, Alice and Bob trust each other without having to think about anything. If they were suing PGP, they have no way of knowing whether or not they can trust the public keys they have for the other user. Now Alice and Bob must check each other?s key fingerprint and compare it against what the other says theirs is. This MUST be done out of band. That means that Alice and Bob need to make a phone call, send a fax or write a letter to get the finger print to the other. The point of secure mail is that you don?t trust the transport mechanism, so you can?t trust fingerprint validation to the same medium.
Wait, there?s more? what happens when Bob is kidnapped by spies? Fired? With PKI, key revocation is centralized and checked against the central source at every use. With PGP the only Bob can revoke his key or Alice can break the trust on her end, assuming she knows that Bob was fired. There are other methods for key revocation depending on how the trust was built, for instance, if someone in the chain of trust were to revoke their trust of Bob, but this is complex and the lack of a standardized trust model leave too much to both chance and error.
The worst part of all this is that you are putting the trust model in the hands of the end user. The average end user does not want to know how it all works and will not perform the proper diligence. This means that the trust model is broken from an operational stand point.
PGP is fantastic for those of us who are nerds and understand complex trust models, but PKI is the only way to go for ease of use and maintaining string trust for end users.
Posted by: markgamache   Posted on: 08/09/05 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

Activation energy vs. activation errors  markgamache | 08/09/05
Excellent points  george_ou | 08/09/05
trust model  pegdashfab | 08/09/05
Try and use spell check at least  george_ou | 08/09/05
Key signing parties... now that's activation energy  markgamache | 08/10/05
But PKI can be flexible too  george_ou | 08/10/05
Invitation: Does George need to get a clue about the new PGP?  4dunk | 08/10/05
You're welcome to email me  george_ou | 08/10/05
IBE Based Encryption  coolwaters | 08/10/05
ibe with conventional pki  pegdashfab | 08/10/05
But PGP Universal generates private keys too  george_ou | 08/10/05
contacting you  4dunk | 08/10/05
The debate was about PKI versus S/MIME  george_ou | 08/10/05
Sorry, title should have been "...PKI versus PGP  george_ou | 08/10/05
Getting beyond rhetoric...  dholakia | 08/10/05
Misdirected anger from PGP Corp  george_ou | 08/10/05
In closing...  dholakia | 08/10/05
Classic deflection  jacec | 08/10/05
Have you tried getting a 'free' certificate?  cvparsi@... | 08/12/05
Who cares about the name?  george_ou | 08/12/05
SRK vs PKI  christen268 | 01/04/06

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Meet Doc