Re: [SPAM] Secure email

Sandro Magi <[email protected]> Tue, 19 Jan 2016 00:43:47 -0500
Newsgroups gmane.comp.capabilities.general
Message-ID <[email protected]>
On 18/01/2016 4:56 PM, Jed Donnelley wrote:
> For typical email use, however, I don't consider key binding a 
> significant issue.  I'd be quite comfortable just accepting a new key 
> binding from anybody sending email to me in nearly all circumstances.  
> Even if I do so without any check or exchange I'm better off than I am 
> now as at least ALL messages will be encrypted and signed - even if 
> the sender isn't necessarily bound to a specific person or institution.

What use would such silent upgrade have over current unencrypted use? I 
can just spoof your friend's address passing along a new key, and start 
a whole new conversation with you without you being any wiser.

The problem with such partial solutions is that they add only a thin 
veneer of easily bypassed security whose deficiencies we'll have to live 
with for another 40 years until the next accidental evolution. I think a 
proper secure key upgrade is necessary for a solution we won't someday 
regret.

> Are you referring to searching my own email archive?  In that case why 
> can't it just be the clear text that is saved and searched?

You certainly could, but it eliminates the possibility of e-mail as a 
third-party service. Unless you think that your e-mail be stored 
unencrypted on these third-party servers as well.

Sandro