Re: dane-openpgp 2nd LC resolution

Viktor Dukhovni <> Mon, 14 March 2016 21:18 UTC

Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id 5063512D791 for <>; Mon, 14 Mar 2016 14:18:31 -0700 (PDT)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001] autolearn=ham autolearn_force=no
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id yajf04IPKY1C for <>; Mon, 14 Mar 2016 14:18:29 -0700 (PDT)
Received: from ( []) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by (Postfix) with ESMTPS id 7973612D78E for <>; Mon, 14 Mar 2016 14:18:29 -0700 (PDT)
Received: by (Postfix, from userid 1034) id 5628E284F45; Mon, 14 Mar 2016 21:18:28 +0000 (UTC)
Date: Mon, 14 Mar 2016 21:18:28 +0000
From: Viktor Dukhovni <>
Subject: Re: dane-openpgp 2nd LC resolution
Message-ID: <>
References: <20160313171101.3215.qmail@ary.lan> <> <> <> <> <>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <>
User-Agent: Mutt/1.5.24 (2015-08-30)
Archived-At: <>
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: IETF-Discussion <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Mon, 14 Mar 2016 21:18:31 -0000

On Mon, Mar 14, 2016 at 01:18:33PM -0700, Doug Barton wrote:

> In this scenario the PGP community has long (and I mean, for 20 years or so)
> advised to ring the person and confirm their key fingerprint (and by
> extension preferred e-mail address) over the phone. I don't see any reason
> why the existence of a DNS mechanism would change that advice.

Because opportunistic encryption won't happen under that requirement.

While not all encryption of email will be opportunistic, it seems
to me that part of the motivation for this experiment is to enable
opportunistic encryption of email sent to people you'll never meet
in person or necessarily be able to contact by means other than

The way that PGP has been used for 20 years has not resulted in
broad adoption of PGP.  This experiment may well not do much better,
(cue Phillip and mathematical mesh which could be what it takes to
make real progress, but too early to tell), but it seems to me that
it is definitely intended to facilitate encrypted first contact.