Re: [openpgp] key distribution by email strategy
Steffen Nurpmeso <steffen@sdaoden.eu> Fri, 11 December 2020 20:28 UTC
Return-Path: <steffen@sdaoden.eu>
X-Original-To: openpgp@ietfa.amsl.com
Delivered-To: openpgp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9C3D93A0F09 for <openpgp@ietfa.amsl.com>; Fri, 11 Dec 2020 12:28:22 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level:
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Kiym4IbMSKMy for <openpgp@ietfa.amsl.com>; Fri, 11 Dec 2020 12:28:20 -0800 (PST)
Received: from sdaoden.eu (sdaoden.eu [217.144.132.164]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B99883A0EDF for <openpgp@ietf.org>; Fri, 11 Dec 2020 12:28:19 -0800 (PST)
Received: by sdaoden.eu (Postfix, from userid 1000) id 5103916057; Fri, 11 Dec 2020 21:28:18 +0100 (CET)
Date: Fri, 11 Dec 2020 21:28:18 +0100
From: Steffen Nurpmeso <steffen@sdaoden.eu>
To: openpgp@ietf.org, Heiko Schaefer <heiko.schaefer@posteo.de>
Message-ID: <20201211202818.bul-I%steffen@sdaoden.eu>
In-Reply-To: <87k0to3yen.fsf@wheatstone.g10code.de>
References: <48be3fcf-cdce-9ef4-655b-63b6dddf9310@kuix.de> <322cc545-4358-ba95-65d5-3f75b7050c0b@kuix.de> <47bcbed4-3832-6ee0-4a39-127af7e455b3@posteo.de> <87k0to3yen.fsf@wheatstone.g10code.de>
Mail-Followup-To: openpgp@ietf.org, Heiko Schaefer <heiko.schaefer@posteo.de>
User-Agent: s-nail v14.9.19-179-g6a1d3a31-dirty
OpenPGP: id=EE19E1C1F2F7054F8D3954D8308964B51883A0DD; url=https://ftp.sdaoden.eu/steffen.asc; preference=signencrypt
BlahBlahBlah: Any stupid boy can crush a beetle. But all the professors in the world can make no bugs.
Archived-At: <https://mailarchive.ietf.org/arch/msg/openpgp/0QsLhqM92f6XcrmLYUINcSaG19A>
Subject: Re: [openpgp] key distribution by email strategy
X-BeenThere: openpgp@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Ongoing discussion of OpenPGP issues." <openpgp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/openpgp>, <mailto:openpgp-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/openpgp/>
List-Post: <mailto:openpgp@ietf.org>
List-Help: <mailto:openpgp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/openpgp>, <mailto:openpgp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 11 Dec 2020 20:28:29 -0000
Werner Koch wrote in <87k0to3yen.fsf@wheatstone.g10code.de>: |On Fri, 11 Dec 2020 13:22, Heiko Schaefer said: | |> The autocrypt standard is established, and quiet a few projects support |> it (https://autocrypt.org/dev-status.html). | |Autocrypt is bound to mail use cases and can't be used in other |environments. Remember that mail is only one use-case; there are many |other important use cases. Also it is a tremendous waste to include kilobytes of data (for usual key types) in each and every mail for nothing, even if the mail as such is not even signed! And if it is signed, then everything you want is included anyway .. no? |Key discovery has never been in the scope of OpenPGP. The standard |provided means to implement systems but does not enforce the use of one. |That limited scope worked very well over the last 23 years. | |Noet that I do not say that such topics ares out of scope for this |mailing list; merely for the OpenPGP standard. In fact, over all the |years this list has also been used as an implementers forum. I personally (not yet supporting OpenPGP for at least one more year, but S/MIME) am also of the opinion that _if_ you discover to have an immediate, real need to start a secure, encrypted communication with someone that you have not yet exchanged keys with, then you can very well send a small message in advance and ask for a public key, or how and where to get it. I admit, i never understood autocrypt. --steffen | |Der Kragenbaer, The moon bear, |der holt sich munter he cheerfully and one by one |einen nach dem anderen runter wa.ks himself off |(By Robert Gernhardt)
- [openpgp] Combining signature with signer's publi… Kai Engert
- Re: [openpgp] Combining signature with signer's p… vedaal
- Re: [openpgp] Combining signature with signer's p… brian m. carlson
- Re: [openpgp] Combining signature with signer's p… Wiktor Kwapisiewicz
- Re: [openpgp] Combining signature with signer's p… Werner Koch
- Re: [openpgp] Combining signature with signer's p… holger krekel
- Re: [openpgp] Combining signature with signer's p… Neal H. Walfield
- Re: [openpgp] Combining signature with signer's p… Neal H. Walfield
- Re: [openpgp] Combining signature with signer's p… Hanno Böck
- Re: [openpgp] Combining signature with signer's p… Wiktor Kwapisiewicz
- Re: [openpgp] Combining signature with signer's p… Kai Engert
- Re: [openpgp] Combining signature with signer's p… Wiktor Kwapisiewicz
- Re: [openpgp] Combining signature with signer's p… Neal H. Walfield
- Re: [openpgp] Combining signature with signer's p… Kai Engert
- Re: [openpgp] Combining signature with signer's p… Neal H. Walfield
- [openpgp] Put Signature in an Email's Header Neal H. Walfield
- Re: [openpgp] Put Signature in an Email's Header Kai Engert
- [openpgp] key distribution by email strategy Kai Engert
- Re: [openpgp] key distribution by email strategy Andrew Gallagher
- Re: [openpgp] key distribution by email strategy Kai Engert
- Re: [openpgp] Put Signature in an Email's Header Bart Butler
- Re: [openpgp] key distribution by email strategy Heiko Schaefer
- Re: [openpgp] key distribution by email strategy Werner Koch
- Re: [openpgp] key distribution by email strategy Steffen Nurpmeso
- Re: [openpgp] key distribution by email strategy Vincent Breitmoser
- Re: [openpgp] key distribution by email strategy Steffen Nurpmeso
- Re: [openpgp] key distribution by email strategy John Scott
- Re: [openpgp] key distribution by email strategy Steffen Nurpmeso
- Re: [openpgp] Put Signature in an Email's Header Daniel Kahn Gillmor
- Re: [openpgp] Put Signature in an Email's Header Benjamin Kaduk