Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You can generally just claim that it was never signed, so you usually need some other mechanism (technical or legal) anyway. This does work the other direction (term of art “non-repudiation”), where the sender can’t claim the message wasn’t theirs or said anything other than what it said. That’s generally considered an undesirable property for messaging systems (because the privacy trade off) but as you point out there are use cases.


Crucial use cases. Official digital signatures use X.509 (including S/MIME) for this exact reason.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: