Re: Proposed Proposed Statement on e-mail encryption at the IETF

Måns Nilsson <mansaxel@besserwisser.org> Tue, 02 June 2015 15:24 UTC

Return-Path: <mansaxel@besserwisser.org>
X-Original-To: ietf@ietfa.amsl.com
Delivered-To: ietf@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 53EB41ACE51 for <ietf@ietfa.amsl.com>; Tue, 2 Jun 2015 08:24:36 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.611
X-Spam-Level:
X-Spam-Status: No, score=-1.611 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, MIME_8BIT_HEADER=0.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 29ShgvmGR-fb for <ietf@ietfa.amsl.com>; Tue, 2 Jun 2015 08:24:34 -0700 (PDT)
Received: from jaja.besserwisser.org (jaja.besserwisser.org [IPv6:2a01:298:4:0:211:43ff:fe36:1299]) by ietfa.amsl.com (Postfix) with ESMTP id B225B1ACE58 for <ietf@ietf.org>; Tue, 2 Jun 2015 08:24:34 -0700 (PDT)
Received: by jaja.besserwisser.org (Postfix, from userid 1004) id 0E4729E62; Tue, 2 Jun 2015 17:24:32 +0200 (CEST)
Date: Tue, 02 Jun 2015 17:24:32 +0200
From: Måns Nilsson <mansaxel@besserwisser.org>
To: Joe Abley <jabley@hopcount.ca>
Subject: Re: Proposed Proposed Statement on e-mail encryption at the IETF
Message-ID: <20150602152432.GE5551@besserwisser.org>
References: <DD88F4E4-6BBA-4610-BB49-3158A26DF55B@hopcount.ca>
MIME-Version: 1.0
Content-Type: multipart/signed; micalg="pgp-sha1"; protocol="application/pgp-signature"; boundary="XuV1QlJbYrcVoo+x"
Content-Disposition: inline
In-Reply-To: <DD88F4E4-6BBA-4610-BB49-3158A26DF55B@hopcount.ca>
X-URL: http://vvv.besserwisser.org
X-Clacks-Overhead: "GNU Sir Terry Pratchett"
X-Purpose: More of everything NOW!
X-happyness: Life is good.
User-Agent: Mutt/1.5.21 (2010-09-15)
Archived-At: <http://mailarchive.ietf.org/arch/msg/ietf/psFsmEfj0dqAzvp1mdCiYZpw3_8>
Cc: IETF Discussion Mailing List <ietf@ietf.org>
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ietf/>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 02 Jun 2015 15:24:36 -0000

Subject: Proposed Proposed Statement on e-mail encryption at the IETF Date: Tue, Jun 02, 2015 at 02:44:47PM +0100 Quoting Joe Abley (jabley@hopcount.ca):

> If the argument that we should use HTTPS everywhere (which I do not disagree with) is reasonable, it feels like an argument about sending encrypted e-mail whenever possible ought to be similarly reasonable. Given that so much of the work of the IETF happens over e-mail, a focus on HTTP seems a bit weird.

++; 

Your e-mail validates perfectly fine. While it does not provide
confidentiality, signing all outgoing e-mail is an excellent dogfooding
mode with immediate benefits;

- You get to build a word-of-mouth cache of keys, 

- Your signing infrastructure gets used, a very good way of keeping it 
  up-to-date, 

- You can with really minor effort upgrade to encrypting email using
  the same cache of keys,

- The multipart MIME signature model works quite nice with mailing lists, 
  as long as one's got a good client. 

- etc. But the major point is keeping things running and current. I've had
  to, on several occasions, wait for people to dig out or regenerate keys,
  or complain over losing private keys/passwords simply because they once
  made the effort to get a key and then bit-rot set in from under-usage.
 
> Note that this is not an attempt to start a conversation about whether
> PGP is usable, or whether S/MIME is better. I will fall off my chair in
> surprise if it doesn't turn into one, though.

The above benefits of signing apply roughly equally well to both methods. 

/Måns, signing all outgoing e-mail. If e-mail from me is not signed,
 something is fishy.
-- 
Måns Nilsson     primary/secondary/besserwisser/machina
MN-1334-RIPE                             +46 705 989668
I'm thinking about DIGITAL READ-OUT systems and computer-generated
IMAGE FORMATIONS ...