Re: Signature Subpacket 10?

Jon Callas <jon@callas.org> Thu, 21 July 2005 00:39 UTC

Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org) by megatron.ietf.org with esmtp (Exim 4.32) id 1DvP5s-0001eG-Ke for openpgp-archive@megatron.ietf.org; Wed, 20 Jul 2005 20:39:20 -0400
Received: from above.proper.com (above.proper.com [208.184.76.39]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id UAA19140 for <openpgp-archive@lists.ietf.org>; Wed, 20 Jul 2005 20:39:18 -0400 (EDT)
Received: from above.proper.com (localhost.vpnc.org [127.0.0.1]) by above.proper.com (8.12.11/8.12.9) with ESMTP id j6L0LaIL035263; Wed, 20 Jul 2005 17:21:36 -0700 (PDT) (envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.11/8.12.9/Submit) id j6L0LavD035262; Wed, 20 Jul 2005 17:21:36 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from merrymeet.com (merrymeet.com [63.73.97.162]) by above.proper.com (8.12.11/8.12.9) with ESMTP id j6L0LZMI035255 for <ietf-openpgp@imc.org>; Wed, 20 Jul 2005 17:21:35 -0700 (PDT) (envelope-from jon@callas.org)
Received: from keys.merrymeet.com (63.73.97.166) by merrymeet.com with ESMTP (Eudora Internet Mail Server X 3.2.6) for <ietf-openpgp@imc.org>; Wed, 20 Jul 2005 17:21:19 -0700
Received: from [63.251.255.205] ([63.251.255.205]) by keys.merrymeet.com (PGP Universal service); Wed, 20 Jul 2005 17:21:33 -0700
X-PGP-Universal: processed; by keys.merrymeet.com on Wed, 20 Jul 2005 17:21:33 -0700
Mime-Version: 1.0 (Apple Message framework v622)
In-Reply-To: <200506301216.29338.iang@systemics.com>
References: <42C3ACFC.9070905@algroup.co.uk> <87wtoc6sso.fsf@wheatstone.g10code.de> <200506301216.29338.iang@systemics.com>
Content-Type: text/plain; charset="US-ASCII"; format="flowed"
Message-Id: <93baa8575e114547bec42e46e1719828@callas.org>
Content-Transfer-Encoding: 7bit
From: Jon Callas <jon@callas.org>
Subject: Re: Signature Subpacket 10?
Date: Wed, 20 Jul 2005 17:21:55 -0700
To: OpenPGP <ietf-openpgp@imc.org>
X-Mailer: Apple Mail (2.622)
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>
Content-Transfer-Encoding: 7bit

On 30 Jun 2005, at 4:16 AM, Ian Grigg wrote:

> A little background.  This was added by the old
> PGP Inc company for commercial users so as to
> escrow email.  If a key had this subpacket, you
> would encrypt to that additional key as well.
>

Not precisely true. It's a way to have data access to any encrypted 
data.

> The notion was that it should go
> in the standard, but that was politically charged
> at the time - indeed Loius Freeh stood up in
> front of Congress and used this very feature as
> proof that it was possible to force all crypto
> programs to escrow messages for the FBI...
>

No. That's completely false. I have no idea where you heard that, but 
that's not at all true.

This is so false that the opposite is true. The FBI hated it because it 
was a completely voluntary system with easy workarounds. The FBI hated 
it, which is one of the amusing ironies about the thing.

> The compromise that was reached was that it
> not be documented in the standard.  I don't
> know if GPG implements it, or even if it the PGP
> line still includes it.  I think architecturally speaking,
> such a feature is better off in the proxy products,
> and layered over the top at the admin level
> rather than put in the tech.  I think it is relatively
> safe to ignore it.
>

It's part of PGP. It's also patented. US patent 6,314,190.

	Jon