Re: Unicode and Security

From: Elliotte Rusty Harold (elharo@metalab.unc.edu)
Date: Thu Feb 07 2002 - 22:45:57 EST


At 5:12 PM -0800 2/7/02, Barry Caplan wrote:

On what basis can "Elliotte" know that a message purported to be from
"Barry Caplan" actually is from "Barry Caplan", or that there even is
a "Barry Caplan"? The person writing this, who claims to be "Barry
Caplan", has never met anyone named "Elliotte Rusty Harold" to the
best of his recollection. He ("Barry Caplan") does claim to
personally be acquainted with many others on this list though - hi -
sorry I missed you in DC! :)

My point is exactly that I have no knowledge of this, but trust is
not about knowledge. Trust is a decision made in the human brain on a
not necessarily rational basis. In a rational world, trust would only
be given to statements with some level of proof. We do not live in
this rational world. In practice untrustworthy entities will be
trusted both as to identity and other statements. Our system should
be robust in the face of this.

-- 

+-----------------------+------------------------+-------------------+ | Elliotte Rusty Harold | elharo@metalab.unc.edu | Writer/Programmer | +-----------------------+------------------------+-------------------+ | The XML Bible, 2nd Edition (Hungry Minds, 2001) | | http://www.ibiblio.org/xml/books/bible2/ | | http://www.amazon.com/exec/obidos/ISBN=0764547607/cafeaulaitA/ | +----------------------------------+---------------------------------+ | Read Cafe au Lait for Java news: http://www.cafeaulait.org/ | | Read Cafe con Leche for XML news: http://www.ibiblio.org/xml/ | +----------------------------------+---------------------------------+



This archive was generated by hypermail 2.1.2 : Thu Feb 07 2002 - 23:07:23 EST