Announcing httpsy://, a YURL scheme

Perry E. Metzger perry at piermont.com
Wed Jul 16 11:26:12 EDT 2003


Ian Grigg <iang at systemics.com> writes:
> Michael_Heyman at NAI.com wrote:
> 
> > A YURL aware search engine may find multiple independent references to a
> > YURL, thus giving you parallel reporting channels, and increasing trust.
> > Of course, this method differs from the YURL method for trust. The
> > parallel channel method assigns a trust value to a site by querying the
> > YURL aware search engine.
> 
> That's an extraordinarily good idea!  It reminds

It seems to me to be more "a bad idea, fully realized".

I'll repeat:

1) The "YURL" makes key management and replacement effectively
   impossible.
2) It leads to situations in which you have no way to know what sort
   of trust relationship you have for the documents you're looking at.
3) It is impossible for people to determine that a "YURL" actually is
   what it claims it is, given that most people can't actually
   remember one hash, let alone large numbers of them, etc.

Those are just some of the more obvious issues.

Perry

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo at metzdowd.com



More information about the cryptography mailing list