Re: Domain security a registry issue (WAS: Re: More Stolen Domains -- not FUD)

From: Ross Wm. Rader (ross@tucows.com)
Date: Tue Jan 18 2005 - 23:49:06 EST


On 1/18/2005 11:40 PM Roger B.A. Klorese noted that:

> No, they can't.
>
> Anyone can pretend they *represent* you with very little trouble.

Please don't put words in my mouth. The fundamental issue is that email
is an inherently insecure mechanism. It allows others to represent
themselves, not as "my spokesperson", but as "me". Somehow, it remains a
fundamental part of the authentication process for all domain related
transactions.

Changing the transaction authorization process ("Yes, I requested that")
does not change the identity assertion and authentication issue (I am
who I say I am and I have the authority to undertake this transaction").

-- 
Regards,

-rwr

"In the modern world the intelligence of public opinion is the one indispensable condition for social progress." - Charles W. Eliot (1834 - 1926)



This archive was generated by hypermail 2.1.3 : Mon Jan 31 2005 - 23:00:02 EST