-> Ed Gerck's example does not illustrate his point but the opposite.  If
-> I did not sign the certificate granting me access to the damaged site,
-> there is no reason whatever to suppose that I had anything to do with
-> the intrusion.  

That's exactly my point. You are not liable if you don't sign.

That's why I proposed an asymmetric situation:

you MUST sign but the verifier MAY check your signature. 

There is no implied overhead on the verifier's side and everyone is as
protected as they wish.

Ed Gerck


Ed Gerck
