>Associating a sender within authenticated identity is a really bad idea.

Woops. Getting dotty in my upper middle age...

That's what I get for not paying attention. 

Eric's absolutely right. There is no need, whatsoever, for "authenticated identity", whatever that is.

All you need is a key. Period. Unassociated with nothing except the mail/money that's being sent. Among other things, that kind of thing is implicit in various bearer-transaction financial cryptography protocols.

Certification hierarchies are neither, and the ultimate CRL is to ping the signer in real-time.

Etc, Etc., yaddayaddayadda...

Who thinks that "identity" is a mystical concept, and, as such, is not worthy of much serious thought.
