[
Lists Home |
Date Index |
Thread Index
]
> If I have the information, encrypt it, and you decrypt
> it then how can anyone know, when those bits show up somewhere on
> Gnutella, who exposed it?
With public-key crypto, it is at least possible to audit things and
"prove" that one party wasn't the discloser. Particularly, in a
multi-party transaction, the intermediaries aren't suspect. With SSL,
each end MUST share the session key, so intermediaries are suspect.
BTW, since a number of followons have said that URL's are opaque, it would
seem that a URL can be partially encrypted and fit into the REST
architecture.
/r$
|