Re: [openpgp] Shared OpenPGP keys for use in test corpuses

Daniel Kahn Gillmor <dkg@fifthhorseman.net> Fri, 18 October 2019 18:53 UTC

Return-Path: <dkg@fifthhorseman.net>
X-Original-To: openpgp@ietfa.amsl.com
Delivered-To: openpgp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 15F31120811 for <openpgp@ietfa.amsl.com>; Fri, 18 Oct 2019 11:53:21 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.3
X-Spam-Level:
X-Spam-Status: No, score=-4.3 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=neutral reason="invalid (unsupported algorithm ed25519-sha256)" header.d=fifthhorseman.net header.b=mD/L7hav; dkim=pass (2048-bit key) header.d=fifthhorseman.net header.b=Kr+YYnGC
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id PXDPvIVePvgI for <openpgp@ietfa.amsl.com>; Fri, 18 Oct 2019 11:53:19 -0700 (PDT)
Received: from che.mayfirst.org (che.mayfirst.org [162.247.75.118]) (using TLSv1.2 with cipher ADH-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C2C25120800 for <openpgp@ietf.org>; Fri, 18 Oct 2019 11:53:18 -0700 (PDT)
DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/simple; d=fifthhorseman.net; i=@fifthhorseman.net; q=dns/txt; s=2019; t=1571424796; h=from : to : cc : subject : in-reply-to : references : date : message-id : mime-version : content-type : from; bh=KTKbqX8/YEIrP2tmHRndl4+H7F/KGFFyicYH+zDtQAQ=; b=mD/L7hav36N+VSsMQjOlxgZizvShkoqNEd4G5vcPNep8tKOaOE2FMsPS g37KPqXbmmt4MMg1fBbVPgl5IKBbAw==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=fifthhorseman.net; i=@fifthhorseman.net; q=dns/txt; s=2019rsa; t=1571424796; h=from : to : cc : subject : in-reply-to : references : date : message-id : mime-version : content-type : from; bh=KTKbqX8/YEIrP2tmHRndl4+H7F/KGFFyicYH+zDtQAQ=; b=Kr+YYnGCDDB5rad6G3RdcMNwHI1OYE7Xk9CxA6miNQoVlbYguG6BPXnt 5tZZCjo1h674JoX/mYgXz2NlB2W2rI2udhQOgeC90osoVLRvQmDPWnMRu6 m4NjLrABsd/Mn52maNbyewK9DD3TS5iWnAzU/+VSUuyDXBDkLi/+NKWMuM 4pIo/oNNBiFegJE8ZoobymwEhV8cr6DX1n2sIGasiITk6ho+Spn0bNLy3c 7ItxcIdcocuNzIu9ciYjHHD/HQ7SPT1XAbAvphLI+pqS6C45Q48XD5RmX/ Cue1urug6wO8WLf3jB/tiLKRdr4SyD8tB6viwuUkMjKF5tncQa49RA==
Received: from fifthhorseman.net (unknown [38.109.115.130]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by che.mayfirst.org (Postfix) with ESMTPSA id E9F28F9A5; Fri, 18 Oct 2019 14:53:15 -0400 (EDT)
Received: by fifthhorseman.net (Postfix, from userid 1000) id C7BCA204BB; Fri, 18 Oct 2019 14:47:27 -0400 (EDT)
From: Daniel Kahn Gillmor <dkg@fifthhorseman.net>
To: Phillip Hallam-Baker <phill@hallambaker.com>, Bjarni Runar Einarsson <bre@mailpile.is>
Cc: IETF OpenPGP <openpgp@ietf.org>
In-Reply-To: <CAMm+LwhscJv=eG8ta+9MQqeSyQy3JN6LCNcg8WoatRyJu-spng@mail.gmail.com>
References: <CAMm+LwiPuVKKP4geKvzPfwayt9ywbS_s5zFChU=cYg7qZ5hBhA@mail.gmail.com> <E6tMQg75su4YqMrAjArkCtN89pHFHaw9EAF94ULX2385@mailpile> <CAMm+LwhscJv=eG8ta+9MQqeSyQy3JN6LCNcg8WoatRyJu-spng@mail.gmail.com>
Autocrypt: addr=dkg@fifthhorseman.net; prefer-encrypt=mutual; keydata= mDMEXEK/AhYJKwYBBAHaRw8BAQdAr/gSROcn+6m8ijTN0DV9AahoHGafy52RRkhCZVwxhEe0K0Rh bmllbCBLYWhuIEdpbGxtb3IgPGRrZ0BmaWZ0aGhvcnNlbWFuLm5ldD6ImQQTFggAQQIbAQUJA8Jn AAULCQgHAgYVCgkICwIEFgIDAQIeAQIXgBYhBMS8Lds4zOlkhevpwvIGkReQOOXGBQJcQsbzAhkB AAoJEPIGkReQOOXG4fkBAO1joRxqAZY57PjdzGieXLpluk9RkWa3ufkt3YUVEpH/AP9c+pgIxtyW +FwMQRjlqljuj8amdN4zuEqaCy4hhz/1DbgzBFxCv4sWCSsGAQQB2kcPAQEHQERSZxSPmgtdw6nN u7uxY7bzb9TnPrGAOp9kClBLRwGfiPUEGBYIACYWIQTEvC3bOMzpZIXr6cLyBpEXkDjlxgUCXEK/ iwIbAgUJAeEzgACBCRDyBpEXkDjlxnYgBBkWCAAdFiEEyQ5tNiAKG5IqFQnndhgZZSmuX/gFAlxC v4sACgkQdhgZZSmuX/iVWgD/fCU4ONzgy8w8UCHGmrmIZfDvdhg512NIBfx+Mz9ls5kA/Rq97vz4 z48MFuBdCuu0W/fVqVjnY7LN5n+CQJwGC0MIA7QA/RyY7Sz2gFIOcrns0RpoHr+3WI+won3xCD8+ sVXSHZvCAP98HCjDnw/b0lGuCR7coTXKLIM44/LFWgXAdZjm1wjODbg4BFxCv50SCisGAQQBl1UB BQEBB0BG4iXnHX/fs35NWKMWQTQoRI7oiAUt0wJHFFJbomxXbAMBCAeIfgQYFggAJhYhBMS8Lds4 zOlkhevpwvIGkReQOOXGBQJcQr+dAhsMBQkB4TOAAAoJEPIGkReQOOXGe/cBAPlek5d9xzcXUn/D kY6jKmxe26CTws3ZkbK6Aa5Ey/qKAP0VuPQSCRxA7RKfcB/XrEphfUFkraL06Xn/xGwJ+D0hCw==
Date: Fri, 18 Oct 2019 14:47:27 -0400
Message-ID: <87v9sl51s0.fsf@fifthhorseman.net>
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg="pgp-sha512"; protocol="application/pgp-signature"
Archived-At: <https://mailarchive.ietf.org/arch/msg/openpgp/OOTh5xgq8lUeNfDDe19fRsDCMnQ>
Subject: Re: [openpgp] Shared OpenPGP keys for use in test corpuses
X-BeenThere: openpgp@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Ongoing discussion of OpenPGP issues." <openpgp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/openpgp>, <mailto:openpgp-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/openpgp/>
List-Post: <mailto:openpgp@ietf.org>
List-Help: <mailto:openpgp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/openpgp>, <mailto:openpgp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 18 Oct 2019 18:53:21 -0000

On Fri 2019-10-18 09:00:42 -0400, Phillip Hallam-Baker wrote:
> Saying that you have technical objections which you will not reveal is
> incredibly rude. Either state your objections so they can be responded to
> or don't state them at all.

Can we tone it down a bit?  Bjarni's objections seem explicitly stated
to me: he's objecting on the grounds of simplicity.  The draft he points
to (which i'm a co-author on) provides material that people can use
today, without any additional effort.

Phil's proposal offers a wider feature set, it's true, but requires more
development of consensus about how to design the key derivation, and
also requires more work on the side of implementers.

Standards develoment can support both of these approaches, there's no
reason to queue one behind the other.

       --dkg