![]() |
|
FastMail Forum All posts relating to FastMail.FM should go here: suggestions, comments, requests for help, complaints, technical issues etc. |
![]() |
|
Thread Tools |
![]() |
#1 |
Senior Member
Join Date: Aug 2002
Location: Milan, Italy
Posts: 142
|
Thawte's Public Certification
Hi,
I'm thinking of setting myself up with a Thawte's personal email certificate - a digital signature if I have understood correctly. This may help avoid some of the problems with virii spoofing my mail address. Before I sign up, I thought I would post here and see if anyone else does this, and what they think. I have not heard of Thawte, some I am a little reluctant to go giving them the amount of personal info which is required for the sign-up - which is free, by the way. If you would like to know more about this service go here: Thawte Let me know what you think and if this type of service will work with FM. Thanks, AlexR Last edited by AlexR : 26 Mar 2004 at 11:53 PM. |
![]() |
![]() |
![]() |
#3 |
Senior Member
Join Date: Aug 2002
Location: Milan, Italy
Posts: 142
|
Fixed the link - must've hit return.
Thanks Daniel - and yes I did mean where you aimed your link. A |
![]() |
![]() |
![]() |
#4 |
Master of the @
Join Date: Nov 2002
Location: Canada
Posts: 1,015
|
I've heard of them. I think they're well respected.
It will not work with FM's web interface. You would need to use an email client that supports this type of certificates, but I think most major clients do (such as Outlook Express, Mozilla, etc). |
![]() |
![]() |
![]() |
#5 |
Senior Member
Join Date: Aug 2002
Location: Milan, Italy
Posts: 142
|
Thanks akorvemaker - that's interesting - but I'd like to hear from one or two more people and hopefully someone who uses one of these certificates. - before I go and sign up....free is a good price - but your don't often get much for nothing (unless it is open source software that is - one major exception to the rule
![]() A |
![]() |
![]() |
![]() |
#6 | |
Senior Member
Join Date: May 2003
Location: Cambridgeshire, UK
Posts: 155
|
Quote:
I think it would only become of value if you used their "notary" system (basically volunteers in various places throughout the world). You go to see a couple of notaries, they take a copy of personal documentation (e.g. passport or something) and give you points. When you have enough points Thawte puts your name in your certificate. Thawte issues Fastmail's https certificate. Simon |
|
![]() |
![]() |
![]() |
#7 | |
Senior Member
Join Date: Sep 2003
Location: Atlanta, GA
Posts: 114
|
Re: Thawte's Public Certification
Quote:
The nice thing about the certificate is that it is authenticated against your e-mail address -- i.e. it is tied to your unique ID. The strength of these certificates over GPG/PGP is that I can create a RSA key pair for anyone I want. However, Diffie-Hellman key exchange fixes up this problem because you can obtain my public key from a key server, even if someone else registers my unique ID (e-mail address) on the server. Even if you have and use my spoofed public key, the message will still be secure because the person who spoofed the key doesn't have a copy of the message. The combination of an X.509 certificate (verifies you are who you say you are) and public key encryption (ties a unique identifier to a particular encryption key-pair) makes you reasonably assured that you are talking (securly) to someone. So, is it useful? I know fewer people (1) that have certificates than have GPG/PGP keys (5 in my keyring right now that I use for e-mail with any frequency). If you do this, though, check our Thunderbird. It's got (with GPG) decent support for encrypting and decrypting messages and key management. It's free (whereas the PGP solution costs ~$50). With the certificate, for it to be really useful, you should sign every outgoing e-mail with it. This precludes, though, the use of the web interface. But it is useful for signing and verifying authenticity, just like SSL certificates are useful for verifying the site you are doing business with is the site that you're securly communicating to. tim |
|
![]() |
![]() |
![]() |
#8 |
Member
Join Date: Mar 2004
Posts: 72
|
I've been using Thawte free cert w/ Outlook and Outlook Express for two years (for encryption purposes only). No problem so far.
As for personal info, I think I was able to go with a minimum amount. |
![]() |
![]() |
![]() |
#9 |
Cornerstone of the Community
Join Date: Sep 2002
Location: SF, CA
Posts: 700
|
I also use Thawte certificates for my email...they are very well known and well respected.
|
![]() |
![]() |
![]() |
#10 |
Essential Contributor
Join Date: Dec 2002
Location: Los Angeles
Posts: 365
|
PGP Freeware is available
Freeware versions of PGP are available. Yes, the latest full-on bells and whistles version for XP or OS X costs $50, but I have been using the freeware ver. 7.0.3 for Me for years and if you go to this site, you can find other (more up to date?) versions for other OSs for free:
http://www.pgpi.org/products/pgp/versions/freeware/ |
![]() |
![]() |
![]() |
#11 |
The "e" in e-mail
Join Date: May 2002
Posts: 2,804
|
The key question is: will anyone treat your email in any significantly different way? For example, does your bank accept instuctions via signed email? Does your employer require you to sign or encrypt email?
If the answer to this question is no, then don't waste your time and money. |
![]() |
![]() |