remote-attestation is not required (Re: The bank fraud blame game)

John Levine johnl at iecc.com
Wed Jul 4 14:25:25 EDT 2007


>I think you misread what I said about "BIOS jumper required install".
>
>Ie this is not a one click install from email.  It is something one
>user in 10,000 would even install at all!

If only.  If you can e-mail me a cool widget with directions I can
follow to install it, a virus can e-mail a million people a copy of
itself with installation instructions, too.  Passworded zip viruses
require considerable effort to install.  I was amazed how many people
do it.

Experience says that enough people will follow the instructions, no
matter how many dire warnings you give them, that anything that's user
programmable isn't a security device.

R's,
John

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo at metzdowd.com



More information about the cryptography mailing list