asciilifeform: mircea_popescu: i had two arguments. one is that it dramatically simplifies the design of the cryptotron. (essentially becomes a mildly scriptable bignum calculator.)☟︎
asciilifeform: incidentally usg is so mortally afraid of reconfigurable crypto that it is SPECIFICALLY banned in the export ban list.
asciilifeform: (recall how sha1 ended up perma-fixed in pgp.)
asciilifeform: problem is that key handling mechanisms tend to get baked in.
asciilifeform: he is now free to distribute 10,001 mutated copies of mircea_popescu's key, with user id 'mp@really-mp-bunker.com' and chumps, who were never properly introduced to mp in meatspace, will send mail to this addr, where it will be transparently forwarded to mp with new headers.
asciilifeform: mircea_popescu: you take an inch from enemy, but give him many more:☟︎
asciilifeform: the one nitpick is that you cannot sign with an fp.
asciilifeform: (recall, it is quite simple to generate the public modulus from it)
asciilifeform: mircea_popescu: what would enemy win if he ~could~ reconstruct the one element he cannot derive from the ciphertext, the userid string ?
asciilifeform: sooo if mircea_popescu gets a new userid (say he throws out his polimedia domain because dns is run by hitler) i have to compare the mods manually ?
asciilifeform: 'this item assures me that it has such-and-such structure.'
asciilifeform: rather, it was a kind of strong checksum.
asciilifeform: mircea_popescu: if phrased this way, it sounds quite laughable. but this was never the point of selfsig
asciilifeform: mircea_popescu: i quite agree. if mircea_popescu wants to distribute his own key without selfsig in the sexpr, he is welcome to.
asciilifeform: but it do NOT see the win from letting any arbitrary bit of binary garbage pass itself off as a valid rsa key + userid set.
asciilifeform: phf: i have no dispute re packaging the sig separately.
asciilifeform: well smart money bets that it isn't keygen-side (or it would have valid new sigs.)
asciilifeform: if selfsig did not exist, we would have considerably less clue re where 'mirrorolade' came from.