Skip to main content

Private Messaging In Public Forums

We have introduced private messaging over public forums in Certisfy, ie you can create and post encrypted messages in public(online) forums via Certisfy private message links. 


You can also add a Certisfy link to your profile (or an appropriate place such as a web page) that will allow someone clicking on it to create a message that can be encrypted and sent/posted where appropriate.


To allow others to encrypt messages for you, you'll first have to create a certificate if you don't already have one. Then copy an encryption URL from the certificate that you then share with others who may want to send/post a private message to you.

In cases where a private message link is via an non-trusted source (internet at large), it is best to link private messaging to verified IDs (could be anonymous), that way a user can be sure their private message is going to the expected party. 

This ability is supported by allowing users to trigger the message encryption from a verification screen, meaning they'll encrypt with the certificate associated with the verification.


Private messaging via Certisfy is not breaking new ground in terms of the ability to easily take advantage of private messaging using public key cryptography, but it is a neat enhancement that Certisfy users will find useful. The ability to link private messaging to trusted recipients is also something that adds value.

Here's a demo showing how to use the feature:


 

Comments

Popular posts from this blog

From a secrecy model of information security to a usage authentication model

We continue to be plagued by data breaches, password and credit card dumps, healthcare records...etc. One of the reasons many of these breaches continue to be devastating and effective for cyber criminals is because our current information use infrastructure/architecture relies on secrecy as the primary mode for preventing the misuse of information. Secrecy simply means only the people who have the right to use a bit of information have access to it, when that assumption breaks down as it does with data breaches, the related information can lose some or all its value. For instance a compromised credit/debit card number means getting a new number. A compromised password database means changing the passwords...etc Secrecy has its use as a privacy preserving mechanism but is fairly flawed as an information usage authentication mechanism. The idea of secrecy as the mechanism for controlling the use of information is deeply ingrained, so much so that even people who should know better often...

How to prevent being scammed via phone calls using Certisfy

Just as we are plagued by data breaches because of our reliance on secrecy as our model of trust assertion instead of just-in-time information verification, we are similarly plagued by scams related to our inability to verify unknown contacts.  Calls, text messages, emails, etc from unknown sources are now a major source of scams, cyber extortion and such. As was demonstrated here , Certisfy stickers backed by cryptographic certificate signatures can address this type of trust problem too. If for instance your doctor's office or other place of business that you have a legitimate business relationship with calls you, they can simply begin the message with a sticker code such as below. You can put that sticker code in the Certisfy app and verify the identity and related information, including for the contact source identifier (phone number, email address...etc).  If a message doesn't start with a verifiable sticker code, you drop it immediately, this effectively kills all such ...

The dubiousness of digitized signature services

Notice I referred to "digitized" instead of digital, this is a very important distinction. These services essentially offer ways to transport handwritten scribbles into digital processes. They can be anything from attaching a Microsoft paint scribble or a scan of one written on a piece of paper, to custom font generation that makes  your signature look like you are a former president of the united states. I wont mention any such services by name but if you've purchased a house or engaged in any sort of contract paperwork activity (leases..etc) you have likely encountered these services. Last I checked, one of these companies is worth north of $40B, no doubt reflecting the size of the market for such services. First, what is the purpose of any signature? as the name suggests, it is primarily to ascribe provenance to something, be it an abstract thing such as a legal agreement expressed in writing or a physical object such as a painting. We also use the notion of signature ...