1 Jun 11:57
Re: key IDs
Morgan Collett <morgan.collett <at> collabora.co.uk>
2007-06-01 09:57:28 GMT
2007-06-01 09:57:28 GMT
Simon McVittie wrote: > Impersonating another child would require a preimage attack, as I understand it > (i.e. the ability to construct a key with a desired hash). It seems > reasonable that we don't defend against preimage attacks. I agree. I don't think anyone can, at this stage... >> For the unique identifier stuff, could we at some future point do a >> 'keyid2/' (or some other prefix) meaning that this is an identifier in a >> different space? > > OK, here's a proposal: > > * The generated JIDs have a prefix ending with a dot, which is the algorithm > by which they were generated. > > * No prefix means hex(SHA-1(Base64(key material))) as we currently do. > This is deprecated and support will be removed before we ship. :) > * We define a prefix to switch to now, perhaps "sha1." meaning > hex(SHA1(key material)). We could consider switching from hex to Base32 > (which would give us JIDs half as long for the same hash length), or to a > stronger hash algorithm, straight away. The Base32 pad character would have > to be changed from "=" to "_" to be valid in both JIDs and object-paths, but > that's easy. Base64 is unsuitable since the user part of a JID is > case-insensitive. > > * Everything else containing a dot is reserved for future expansion.(Continue reading)
I'd like to spend a day this coming week working through Alan's
50-of-100 notes, and the use cases you have in mind. (Alan, can we
make the document public?)
As for presentations and slides, Etoys remains for the time being our
supported method for importing .ppt -- Rebecca, have you tried this?
Were you asking for something more specific?
SJ
ps - That might also be a good opportunity to think about what a
generic bundle looks like.
On 6/2/07, Alan Kay <alan.kay <at> squeakland.org> wrote:
> You might want to check out what Etoys actually does and is. (Hint:
> it covers your desiderata beIow pretty well.)
>
> I suggest perusing the document that I made up for the OLPC countries
> meeting a few weeks ago. Nia Lewis will probably have a copy.
>
> Cheers,
>
> Alan
>
RSS Feed