Re: [Enigmail] Enigmail 2.0.12 available
Patrick Brunschwig <[email protected]>
| Newsgroups | gmane.comp.mozilla.enigmail.general |
|---|---|
| Message-ID | <[email protected]> |
On 10.07.2019 10:43, Dmitry Alexandrov wrote: > Patrick Brunschwig <[email protected]> wrote: >> On 10.07.2019 05:55, Dmitry Alexandrov wrote: >>> Patrick Brunschwig <[email protected]> wrote: >>>> I am happy to announce Enigmail v2.0.12 for Thunderbird 60.* >>> >>>> This release sets the default keyserver to keys.openpgp.org in order to mitigate the SKS Keyserver Network Attack [1]. This change is applied unconditionally for all installations, except if the default keyserver is set to an ldap server. >>> >>> Given that the issue is now mitigated in GPG, when will reverting this back be scheduled? >> >> I won't revert this change for two reasons: >> >> 1. It will take weeks to months until the majority of the Windows and macOS systems will have updated (which first requires the availability of new versions of gpg4win, GPGTools, GpgOSX etc). > > Well, that’s exactly the kind of answer I hoped to get: a stub will be reverted when such and such updates are published. But I see now, I was too optimistic. :-\ > >> 2. As I already said publicly, the default in Enigmail 2.1 will be keys.openpgp.org. The change is now just a little earlier than anticipated. > > So, just to clarify, you intentionally replaced the standard distributed network with some freshly established private service, where centralized control is _not_ a child illness, but a design: > > | Several folks offered to help out by "running a Hagrid server instance". We very much appreciate the offer, but we will probably never have an "open" federation model like SKS, where everyone can run an instance and become part of a "pool". > — https://keys.openpgp.org/about/faq Even though I currently don't have an active role with Hagrid, I am one of its initiators. I'm fully aware of the pros and cons. I honestly strongly disagree with the idea that a key directory (and Hagrid is not more than that) must be decentralized. If you want decentralized key distribution/lookup, then use Autocrypt and WKD, which are both part or Enigmail and which are both used before keyserver lookup. Furthermore, you rely on Enigmail, which is developed by me, myself and I -- with very little help from others. That is, many people rely on a centralized system sitting above my shoulders for their encrypted communication. Do you think that's any better or worse than using a centralized directory for key lookup? > moreover, pushed that change to setups of the most old users, — and found all of that absolutely okay? Given the circumstances - yes. My plan was to set the new default, but to NOT touch the existing installations. But the SKS issue forced me to go that way. This is not a problem that only affects a few dozen users who are savvy enough to handle this, or to look up resources for fixing this. This is something that affects many thousand people, if not more. And it is simply out of question for me to spend my free time on handling the support requests of all these users individually. And this *will* happen. I just had 2 support requests this morning. And as I said - I can't undo that because people are too lazy with updating their software. -Patrick _______________________________________________ enigmail-users mailing list [email protected] To unsubscribe or make changes to your subscription click here: https://admin.hostpoint.ch/mailman/listinfo/enigmail-users_enigmail.net
signature.asc
(application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEET5+J9VBawdGiYGMc2xGHud1faTsFAl0lzuYACgkQ2xGHud1f aTu/ZA/9F6Q3gmVT44xuh95PyOfts4sGwrfS05YEMfIJi9eow5SDD6syhIwWtY/Q CVuaDtEJlswuYhuDm273XoiqgL7crLe6NwFqeBsoPpzZgtORn8E6IY++Ko9hCPEE bJ1pM1VhDLbd35+LHCb6N7iVErhOGLWW5YtWN1zCByReDfw6ibiC+LPwCsznevnY EHflTsrYZZU2JvNj9CviVjKBPDfryAll9SGRPQtylXK/CZwt/Uh0shXmyUxZRYWJ hmcZa7BRwT0B0EFTOprY2nJmkFHY1TXJUZlK/gFabWZzQJD8U3C5l+z+fbI4L7t9 nxSnQkYART/btrmSwqrNnTXYwllG4xpiBhj3TluYudB+MNYz0ZzPDeN5XejD5g6H ZNn+rJtlX46WqpT449s+oVLGUXozhVux8pV+ArTaDT2GKGQeYigZcGiONB/B+/IN K3lFHIJvfh7t4VcFe9zxpeulACEkEkIF1mB70lyKlaJb7LkTd07jDuolkPQTH/WO lyV93RIgiRKUL+P4/PhGLePZq8pZWtYQJC57ufmkI8JWZI0IiFjzdszhAMogAp85 kaewbbUdGi/HSRhk7Tm5xoIms33KxQ7bSYA/fJF70P3u1YUdlFYMjPaa/mTojrId n8U40qsCQwdHvmH48GfmrTth5EX8hhBD3DcsiixD5BCYjj+QLX0= =5RWl -----END PGP SIGNATURE-----