Re: [SPAM] Secure email
Sandro Magi <[email protected]> Tue, 19 Jan 2016 00:43:47 -0500
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <[email protected]> |
On 18/01/2016 4:56 PM, Jed Donnelley wrote: > For typical email use, however, I don't consider key binding a > significant issue. I'd be quite comfortable just accepting a new key > binding from anybody sending email to me in nearly all circumstances. > Even if I do so without any check or exchange I'm better off than I am > now as at least ALL messages will be encrypted and signed - even if > the sender isn't necessarily bound to a specific person or institution. What use would such silent upgrade have over current unencrypted use? I can just spoof your friend's address passing along a new key, and start a whole new conversation with you without you being any wiser. The problem with such partial solutions is that they add only a thin veneer of easily bypassed security whose deficiencies we'll have to live with for another 40 years until the next accidental evolution. I think a proper secure key upgrade is necessary for a solution we won't someday regret. > Are you referring to searching my own email archive? In that case why > can't it just be the clear text that is saved and searched? You certainly could, but it eliminates the possibility of e-mail as a third-party service. Unless you think that your e-mail be stored unencrypted on these third-party servers as well. Sandro