Re: not really pgp signing in van

"John Levine" <johnl@taugh.com> Tue, 10 September 2013 01:07 UTC

Return-Path: <johnl@iecc.com>
X-Original-To: ietf@ietfa.amsl.com
Delivered-To: ietf@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A5DE121E8160 for <ietf@ietfa.amsl.com>; Mon, 9 Sep 2013 18:07:48 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -101.949
X-Spam-Level:
X-Spam-Status: No, score=-101.949 tagged_above=-999 required=5 tests=[AWL=0.650, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id H7xE3vx5ClaP for <ietf@ietfa.amsl.com>; Mon, 9 Sep 2013 18:07:44 -0700 (PDT)
Received: from leila.iecc.com (leila6.iecc.com [IPv6:2001:470:1f07:1126:0:4c:6569:6c61]) by ietfa.amsl.com (Postfix) with ESMTP id 2024721E8156 for <ietf@ietf.org>; Mon, 9 Sep 2013 18:07:43 -0700 (PDT)
Received: (qmail 62749 invoked from network); 10 Sep 2013 01:07:41 -0000
Received: from leila.iecc.com (64.57.183.34) by mail1.iecc.com with QMQP; 10 Sep 2013 01:07:41 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=simple; d=iecc.com; h=date:message-id:from:to:cc:subject:in-reply-to:mime-version:content-type:content-transfer-encoding; s=522e70dd.xn--9vv.k1309; i=johnl@user.iecc.com; bh=ofB6hX5YSAlIz3S0Ekl5q7BFcwIPfbC723beEOhdKv0=; b=AioSjt7a2lZv/cVoBzoXlHVOZozFM9cID9S7dQcI4DqDXl2HxHCvbGPG6yTr+Ekr1R6voC+axsi77Xvur5FuF1xPzjSQ9BD2V30/5lxGRxujhLB4aYg2vs1tmFLFe5lhC1OSUGambnTgZu7+80Ic8UPciLHMzrq4afXjwINFL2ayV7/nN1U5xgOa1Gj35A+JnRTgoWGbO7pC69WgUiy43LN64GXD9NncJTrfabt/2O4BSfpOyIQakrBMC+Xq/TwM
DKIM-Signature: v=1; a=rsa-sha256; c=simple; d=taugh.com; h=date:message-id:from:to:cc:subject:in-reply-to:mime-version:content-type:content-transfer-encoding; s=522e70dd.xn--9vv.k1309; olt=johnl@user.iecc.com; bh=ofB6hX5YSAlIz3S0Ekl5q7BFcwIPfbC723beEOhdKv0=; b=DcW57ufBxzOnjVsaM++VkDkakoEaM/dzyZrUCvRuXimo61Pk4IpHqLa7qRkmpZrc7aCSx5Yf5jHwkhtetgNeyXiz/l5Wt4oX7h/AhQFpu1Mxwskf0ZXvFAnaBxP4gzxbs51+rEtthNv0KSNGls7OHt4rkvY/aSrn5ePlGN2PW762PM6Q45k2KKa4fT0llezooevrwMdlAeJ7MpFoZNiCge1IbYB0YqL4YR4/6ajzdmfcj4uVb8s9G0hHuGigpobu
Date: Tue, 10 Sep 2013 01:07:19 -0000
Message-ID: <20130910010719.33978.qmail@joyce.lan>
From: John Levine <johnl@taugh.com>
To: ietf@ietf.org
Subject: Re: not really pgp signing in van
In-Reply-To: <1604134.0PAONl8GoT@scott-latitude-e6320>
Organization:
X-Headerized: yes
Mime-Version: 1.0
Content-type: text/plain; charset="utf-8"
Content-transfer-encoding: 8bit
Cc: scott@kitterman.com
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ietf>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 10 Sep 2013 01:08:00 -0000

>> Sounds like we're on our way to reinventing S/MIME.  Other than the
>> key signing and distribution (which I agree is a major can of worms)
>> it works remarkably well.
>
>Which sounds kind of like, "Other than that Mrs. Lincoln, how was the play?"

Yes, and no.  PGP and S/MIME each have their own key distribution
problems.  With PGP, it's easy to invent a key, and hard to get other
people's software to trust it.  With S/MIME it's harder to get a key,
but once you have one, the software is all happy.

The MUAs I use (Thunderbird, Alpine, Evolution) support S/MIME a lot
better than they support PGP.  There's typically a one key command or
a button to turn signing and encryption on and off, and they all
automagically import the certs from on incoming mail.

R's,
John