Free Republic
Browse · Search
News/Activism
Topics · Post Article

To: ConservativeMind
I've worked PKI problems for decades. The problem is key management like you say, but it is not the private keys that are managed, but the public keys.

Here's how it works in a nutshell, the user creates a private key, typically in a browser, along with the public key in a certificate request. The cert request is sent off to be signed by a certificate authority. Once signed, the certificate is published and everyone can see it, hence, public key. The private key stays on the user's computer and never leaves.

When someone sends you an encrypted email, they encrypt it with your public key. You decrypt it with your private key. Only you possess the private key. You were issued a certificate with your public key. Businesses and government have the public key, they signed the cert, and the cert expires in a year, hence they are managed. They never have your private key.

97 posted on 12/26/2017 6:24:03 AM PST by palmer (...if we do not have strong families and strong values, then we will be weak and we will not survive)
[ Post Reply | Private Reply | To 93 | View Replies ]


To: palmer

“The private key stays on the user’s computer and never leaves.

When someone sends you an encrypted email, they encrypt it with your public key. You decrypt it with your private key. Only you possess the private key.”

In the above scenario, the company has your private key, too. You are using your company’s email infrastructure and they can block any attempt to use a key they don’t manage on your email.

In the circumstance we are all talking about, the employer has these things (the Government). That’s how they can see all of this.


113 posted on 12/26/2017 8:37:26 AM PST by ConservativeMind (Trump: Befuddling Democrats, Republicans, and the Media for the benefit of the US and all mankind.)
[ Post Reply | Private Reply | To 97 | View Replies ]

To: palmer

This discussion, although a bit of a digression, is very interesting to me in relation to some projects I am currently working on.

What’s your understanding of the potential for ID theft and a resultant theft of PKI Public AND Private Keys?


114 posted on 12/26/2017 9:26:14 AM PST by Hostage (Article V)
[ Post Reply | Private Reply | To 97 | View Replies ]

Free Republic
Browse · Search
News/Activism
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson