Re: [Enigmail] Enigmail 2.0.12 available

Patrick Brunschwig <[email protected]>
Newsgroups gmane.comp.mozilla.enigmail.general
Message-ID <[email protected]>
On 10.07.2019 10:43, Dmitry Alexandrov wrote:
> Patrick Brunschwig <[email protected]> wrote:
>> On 10.07.2019 05:55, Dmitry Alexandrov wrote:
>>> Patrick Brunschwig <[email protected]> wrote:
>>>> I am happy to announce Enigmail v2.0.12 for Thunderbird 60.*
>>>
>>>> This release sets the default keyserver to keys.openpgp.org in order to mitigate the SKS Keyserver Network Attack [1]. This change is applied unconditionally for all installations, except if the default keyserver is set to an ldap server.
>>>
>>> Given that the issue is now mitigated in GPG, when will reverting this back be scheduled?
>>
>> I won't revert this change for two reasons:
>>
>> 1. It will take weeks to months until the majority of the Windows and macOS systems will have updated (which first requires the availability of new versions of gpg4win, GPGTools, GpgOSX etc).
> 
> Well, that’s exactly the kind of answer I hoped to get: a stub will be reverted when such and such updates are published.  But I see now, I was too optimistic.  :-\
> 
>> 2. As I already said publicly, the default in Enigmail 2.1 will be keys.openpgp.org. The change is now just a little earlier than anticipated.
> 
> So, just to clarify, you intentionally replaced the standard distributed network with some freshly established private service, where centralized control is _not_ a child illness, but a design:
> 
> | Several folks offered to help out by "running a Hagrid server instance". We very much appreciate the offer, but we will probably never have an "open" federation model like SKS, where everyone can run an instance and become part of a "pool".
> — https://keys.openpgp.org/about/faq

Even though I currently don't have an active role with Hagrid, I am one
of its initiators. I'm fully aware of the pros and cons.

I honestly strongly disagree with the idea that a key directory (and
Hagrid is not more than that) must be decentralized. If you want
decentralized key distribution/lookup, then use Autocrypt and WKD, which
are both part or Enigmail and which are both used before keyserver lookup.

Furthermore, you rely on Enigmail, which is developed by me, myself and
I -- with very little help from others. That is, many people rely on a
centralized system sitting above my shoulders for their encrypted
communication. Do you think that's any better or worse than using a
centralized directory for key lookup?

> moreover, pushed that change to setups of the most old users, — and found all of that absolutely okay?

Given the circumstances - yes. My plan was to set the new default, but
to NOT touch the existing installations. But the SKS issue forced me to
go that way.

This is not a problem that only affects a few dozen users who are savvy
enough to handle this, or to look up resources for fixing this. This is
something that affects many thousand people, if not more. And it is
simply out of question for me to spend my free time on handling the
support requests of all these users individually. And this *will*
happen. I just had 2 support requests this morning.

And as I said - I can't undo that because people are too lazy with
updating their software.

-Patrick

_______________________________________________
enigmail-users mailing list
[email protected]
To unsubscribe or make changes to your subscription click here:
https://admin.hostpoint.ch/mailman/listinfo/enigmail-users_enigmail.net
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEET5+J9VBawdGiYGMc2xGHud1faTsFAl0lzuYACgkQ2xGHud1f
aTu/ZA/9F6Q3gmVT44xuh95PyOfts4sGwrfS05YEMfIJi9eow5SDD6syhIwWtY/Q
CVuaDtEJlswuYhuDm273XoiqgL7crLe6NwFqeBsoPpzZgtORn8E6IY++Ko9hCPEE
bJ1pM1VhDLbd35+LHCb6N7iVErhOGLWW5YtWN1zCByReDfw6ibiC+LPwCsznevnY
EHflTsrYZZU2JvNj9CviVjKBPDfryAll9SGRPQtylXK/CZwt/Uh0shXmyUxZRYWJ
hmcZa7BRwT0B0EFTOprY2nJmkFHY1TXJUZlK/gFabWZzQJD8U3C5l+z+fbI4L7t9
nxSnQkYART/btrmSwqrNnTXYwllG4xpiBhj3TluYudB+MNYz0ZzPDeN5XejD5g6H
ZNn+rJtlX46WqpT449s+oVLGUXozhVux8pV+ArTaDT2GKGQeYigZcGiONB/B+/IN
K3lFHIJvfh7t4VcFe9zxpeulACEkEkIF1mB70lyKlaJb7LkTd07jDuolkPQTH/WO
lyV93RIgiRKUL+P4/PhGLePZq8pZWtYQJC57ufmkI8JWZI0IiFjzdszhAMogAp85
kaewbbUdGi/HSRhk7Tm5xoIms33KxQ7bSYA/fJF70P3u1YUdlFYMjPaa/mTojrId
n8U40qsCQwdHvmH48GfmrTth5EX8hhBD3DcsiixD5BCYjj+QLX0=
=5RWl
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.