Re: photo support?

David Shaw <dshaw@jabberwocky.com> Mon, 01 July 2002 22:07 UTC

Received: from above.proper.com (mail.proper.com [208.184.76.45]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id SAA06602 for <openpgp-archive@odin.ietf.org>; Mon, 1 Jul 2002 18:07:42 -0400 (EDT)
Received: from localhost (localhost [[UNIX: localhost]]) by above.proper.com (8.11.6/8.11.3) id g61LtWj17846 for ietf-openpgp-bks; Mon, 1 Jul 2002 14:55:32 -0700 (PDT)
Received: from claude.kendall.akamai.com (akafire.akamai.com [65.202.32.10]) by above.proper.com (8.11.6/8.11.3) with ESMTP id g61LtVw17841 for <ietf-openpgp@imc.org>; Mon, 1 Jul 2002 14:55:31 -0700 (PDT)
Received: (from dshaw@localhost) by claude.kendall.akamai.com (8.11.6/8.11.6) id g61LtQ621194 for ietf-openpgp@imc.org; Mon, 1 Jul 2002 17:55:26 -0400
Date: Mon, 01 Jul 2002 17:55:26 -0400
From: David Shaw <dshaw@jabberwocky.com>
To: ietf-openpgp@imc.org
Subject: Re: photo support?
Message-ID: <20020701215526.GD19461@akamai.com>
Mail-Followup-To: ietf-openpgp@imc.org
References: <ilusn33qn5i.fsf@latte.josefsson.org> <OE50o8HKHT0cWL0Wu330000105e@hotmail.com>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
In-Reply-To: <OE50o8HKHT0cWL0Wu330000105e@hotmail.com>
X-PGP-Key: 99242560 / 7D92 FD31 3AB6 F373 4CC5 9CA1 DB69 8D71 9924 2560
X-URL: http://www.jabberwocky.com/
X-Phase-Of-Moon: The Moon is Waning Gibbous (58% of Full)
User-Agent: Mutt/1.5.1i
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>

On Mon, Jul 01, 2002 at 03:49:24PM -0400, vedaal wrote:

> > Is there a standardized way to embed photos in OpenPGP keys?  Anyone
> > interested in writing such a standard?
> 
> as it is now, it is definitely 'different' for PGP and GnuPG.
> 
> PGP compresses the .jpg into the photo id, and does not export it when
> exporting the key.
> 
> GnuPG leaves the .jpg intact as added by the user, and exports it intact as
> part of the .asc
> 
> if PGP downloads a public key with a photo id, that was generated by GnuPG,
> it will export a photo as part of the .asc, but 'altered/compressed'.
> the exported .asc of the public key will be different than the exported .asc
> of the GnuPG key.

Altered or compressed in what way?  If PGP changes the photo, then it
would break all signatures on the photo ID.

PGP does alter the photo when you paste it in (converts it to jpeg and
shrinks it), but once it's in the key, it does not change it.  GnuPG
requires a jpeg from the user and does not change it.  Either of these
is fine, since the spec says nothing about what happens to the photo
before it is placed into the key.

It does not matter if the ascii-armored representation of the key is
different between GnuPG and PGP.  This does not necessarily mean that
the photo has been changed.

David

-- 
   David Shaw  |  dshaw@jabberwocky.com  |  WWW http://www.jabberwocky.com/
+---------------------------------------------------------------------------+
   "There are two major products that come out of Berkeley: LSD and UNIX.
      We don't believe this to be a coincidence." - Jeremy S. Anderson