[cap-talk] Web introductions, fingerprint service

Jed Donnelley capability at webstart.com
Thu Feb 28 02:26:04 EST 2008


At 04:53 PM 2/27/2008, Karp, Alan H wrote:
>Jed wrote:
> >
> > Is that really true?  Even for their entry points?  I
> > don't mind having a site I trust hand me off to another
> > site with a distinct private key.
>
>But then your petname for the site will disappear.  How will you 
>know you're talking to a server in the company?  Maybe some DNS 
>poisoning attack hijacked your session.

Good point.  I've worked some more on this topic (essentially
getting valid pre-loaded Petname Tool entries by using a service
that does validation checking from a variety of sites around
the Internet), but I think perhaps this discussion has gone
on too long for cap-talk?

Does anybody know any other list where they might focus
more on such topics?  I'd like to reach a point whether
I either get confidence that such a service is or is
not possible.

--Jed  http://www.webstart.com/jed-signature.html 



More information about the cap-talk mailing list