[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: CAcert assurance information



Em Qui, 2005-07-14 às 13:35 +0100, Paul Sladen escreveu:
> On Thu, 14 Jul 2005, Gustavo Noronha Silva wrote:
> > Em Qui, 2005-07-14 às 10:08 +0200, Alexander Wirt escreveu:
> > > > 3. Bring 5 printouts of the WoT form[2] to the keysigning
> > > 3 are enough as we can only provide a maximum of 100 points. 
> > I've mailed them requesting extension for that so if they do accept my
> > request I'll be able to give 150 points for people who can identify
> > themselves with 2 official documents.
> 
> I thought the point of CAcert was to be different, by being distributed.
> 
> Now you're trying to circumvent that difference by putting sufficient trust
> liability into one person's hands---Does this not defeat the /entire/ point?

Sorry for taking long time to answer to this; but I think it's specialy
important to discuss this issue since the 'super powers' were indeed
used.

CACert is different from other CA's because you don't go straight to the
"root" to be trusted; the certifying process happens through the
assurers, who are individuals who got assured by the root or by some
other assured.

This is the kind of 'distribution' cacert is about, even if the web of
trust has usually less links pointing to a same node than in the pgp
model.

Anyway, althought Micah gave the maximum points to everyone he assured I
also made sure to also register my assuring of the same people so that
we have more 'nodes' pointing to them, enhancing the web of trust.

I don't think we're losing in trustworthiness and its good to have more
assurers who may increase cacerts' reach.

See ya!

-- 
kov@debian.org: Gustavo Noronha <http://people.debian.org/~kov>
Debian:  <http://www.debian.org>  *  <http://www.debian-br.org>

Attachment: signature.asc
Description: This is a digitally signed message part


Reply to: