Re: Newbie naive question, perhaps - - be kind
Available news archives: comp.lang.tcl - comp.lang.python - comp.security.firewalls - sci.crypt - comp.lang.php - comp.lang.javascript
Google
 
Web news.hping.org


sci.crypt archive

Re: Newbie naive question, perhaps - - be kind

From: Paul Rubin <//phr.cx@NOSPAM.invalid>
Date: Mon Oct 17 2005 - 03:32:54 CEST

Tom McCune <news1@DELETE_THISmccune.cc> writes:
> That is rather obvious - isn't it. But, it does not negate that the
> user may well be capable of installing such software, which is
> obviously the point I was making.

The user MAY be capable of installing software but very well might NOT
be. Why are you so obsessed with shifting inconvenience from the
practitioner (who can hire someone to set up a web site, and who has
to have reasonable basic computer skills to patient data secure and
backed up) over to the patient, who may be near totally computer
illiterate? Spend a few minutes watching an elderly AOL user try to
browse the web and you'll have an idea of what you're up against.
The jokes about mistaking a CD-ROM tray for a cup holder are all true.

I have nothing against PGP for semi-technical users (I was part of the
PGP development group for a while back in the day) but it's totally
wrong for the wide public to communicate with service providers with.
It's not just a matter of installing and running the program; there's
the setup and maintenance of key ring files, the spy vs spy nonsense
of comparing hexadecimal fingerprints, etc. If it takes one minute to
do all that stuff, that's about 59 seconds too long. You really have
to aim at the lowest common denominator.

Also, anyone concerned about security should be very hesitant to
install any new unknown software on their computer. You and I might
know that PGP is ok, but think of someone who has never heard of it.
I can promise you, if my health care provider told me I had to install
any type of unfamiliar software on my PC in order to communicate with
them by email, I'd just say screw it and I'd use the phone. There's
no way I'd install anything like that.

PGP was a great idea in the 1980's. It's the 21st century now, and
there are much easier ways to do these things.
Received on Mon Oct 17 20:48:32 2005