Transport-level encryption with Tcpcrypt
Transport-level encryption with Tcpcrypt
Posted Sep 4, 2010 4:52 UTC (Sat) by zooko (guest, #2589)In reply to: Transport-level encryption with Tcpcrypt by Trelane
Parent article: Transport-level encryption with Tcpcrypt
ftp://cag.lcs.mit.edu/pub/dm/papers/mazieres:thesis.ps.gz
ssh's model which Peter Gutmann calls the "baby-duck" model or "key continuity"
Web of Trust by Phil Zimmermann
The FreeS/WAN project by John Gilmore, Hugh Daniel et al., known as "Opportunistic Encryption".
The Capability Access Control model:
original:
http://www.cs.washington.edu/homes/levy/capabook/Chapter3...
modern synthesis:
http://erights.org/talks/thesis/index.html
Zooko's Triangle and Pet Names:
http://www.skyhunter.com/marcs/petnames/IntroPetNames.html
ZRTP:
http://en.wikipedia.org/wiki/ZRTP
Tahoe-LAFS:
(Those last three are self-citations.)
The overall theme here is that the good ideas about robust decentralized security came originally from systems researchers and hackers, not from cryptographers. Cryptographers traditionally focused on elegant mathematical models and (with almost no explicit justification) they settled on the globe-spanning, centralized, hierarchical security model that we all know and love today as "PKI".
