re: forwarding an encrypted message

"vedaal" <vedaal@hotmail.com> Tue, 09 April 2002 20:54 UTC

Received: from above.proper.com (above.proper.com [208.184.76.39]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id QAA22137 for <openpgp-archive@odin.ietf.org>; Tue, 9 Apr 2002 16:54:44 -0400 (EDT)
Received: by above.proper.com (8.11.6/8.11.3) id g39KdnO11892 for ietf-openpgp-bks; Tue, 9 Apr 2002 13:39:49 -0700 (PDT)
Received: from hotmail.com (oe57.law3.hotmail.com [209.185.240.57]) by above.proper.com (8.11.6/8.11.3) with ESMTP id g39Kdmm11887 for <ietf-openpgp@imc.org>; Tue, 9 Apr 2002 13:39:48 -0700 (PDT)
Received: from mail pickup service by hotmail.com with Microsoft SMTPSVC; Tue, 9 Apr 2002 13:28:35 -0700
X-Originating-IP: [207.127.12.210]
From: vedaal <vedaal@hotmail.com>
To: ietf-openpgp@imc.org
Subject: re: forwarding an encrypted message
Date: Tue, 09 Apr 2002 16:26:55 -0400
MIME-Version: 1.0
Content-Type: text/plain; charset="Windows-1252"
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.50.4807.1700
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4807.1700
Message-ID: <OE57ZElV5tTPEiRZiUi0000d300@hotmail.com>
X-OriginalArrivalTime: 09 Apr 2002 20:28:35.0398 (UTC) FILETIME=[1FAD1660:01C1E005]
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>
Content-Transfer-Encoding: 7bit

-----BEGIN PGP SIGNED MESSAGE-----
Hash: RIPEMD160

- ----- Original Message ----- 
From: "Simon Josefsson" <simon+ietf-openpgp@josefsson.org>
To: "Marc Mutz" <mutz@kde.org>
Cc: <kmail@kde.org>; <ietf-822@imc.org>; <ietf-openpgp@imc.org>
Sent: Tuesday, April 09, 2002 3:32 PM
Subject: Re: Bug#40394: forwarding an encrypted PGP message is useless


> 
> Marc Mutz <mutz@kde.org> writes:
> 
> > What if, in a mail user agent, the user wants to forward an encrypted
> > message? Allow it? Deny it?
> > Re-encrypt or remove encryption?
> >
> > The problem is, of course, that the original sender might not like his
> > encrypted text being sent out in the clear again...
> 
> Then the original sender should not send the text to someone who will
> do that.
> 
> I don't see how the standard could prevent the user from doing
> this. If it is prevented, then it is only the applications' doing, so
> it wouldn't be difficult to override it.  
...
a way to do it, would be to send the original encrypted message using the
throw- keyid switch,

any re-sending of the message would not be able to identify the original
sender,

moreover, the message could also be sent using the option of 'screen
viewing only' so that the plaintext could not be saved,
except tediously by saving a screen shot, or re-typing the message,
both of which can be 'denied' by the original sender, and can be proved by
the forwarder, only by having someone witness the decryption.

hth,

vedaal

-----BEGIN PGP SIGNATURE-----
Version: 6.5.8ckt   build 7      http://www.ipgpp.com/
Comment: { Acts of Kindness better the World, and protect the Soul }
Comment: KeyID: 0x6A05A0B785306D25
Comment: Fingerprint: 96A6 5F71 1C43 8423  D9AE 02FD A711 97BA

iQEVAwUBPLNNBGoFoLeFMG0lAQNFHgf+OmEDLzkChGzImWKeTK7Ma7sojVqGxUtJ
pGCtwK/SEjhxeiX0p+6ejFalP0FTN0xUNMhJ+P+oOW20BEUiSJEGiYOPDnrhThyq
nmg+jC2vgjEzGjdOo/CQ56XUh6ATQ1RRi2U5eahwftpzLQSPgSVrut9H4bmYT5OL
7Hk2MNQj5K1+9IwgjSrajs1DWv0Pbfx7ytrAAB2tnvx+KW6Qb5xQN8qMotbEI744
7q91c8VjMgu4w/L3TlkFigx1d4TJO/ZkFYclTgD43PbiYL3OcYE380MlYXxaD/rm
2JHdyD3jewyhkx+BAxiwaj/po7S45MVeoX5Ke8v7jF//eEBh8qCARQ==
=AT2F
-----END PGP SIGNATURE-----