> Unless you're talking to something someone just set up that
> claims cheerfully that any and all connections on that machine are
> owned by Rahul Desi. In other words, how do I know I am talking to
> an identity server at all?
He never said you did. What he said was you know you are getting reasonable
information or talking to a cracked machine. The completely distrustful
disgards the information from the former. Thanks, we'll take what we can
get in this messy world.
> If you're running a service that claims to be an "Identification"
> service, it should be something that I can trust, or it's a toy and
> you should shut it down. Ident says, "Trust Me."
The completely trustful are equal fools to the completely paranoid.
References:
|
|