Re: [Enigmail] Enigmail 2.0.12 available
Dmitry Alexandrov <[email protected]>
| Newsgroups | gmane.comp.mozilla.enigmail.general |
|---|---|
| Message-ID | <[email protected]> |
Patrick Brunschwig <[email protected]> wrote: > On 10.07.2019 10:43, Dmitry Alexandrov wrote: >> Patrick Brunschwig <[email protected]> wrote: >>> On 10.07.2019 05:55, Dmitry Alexandrov wrote: >>>> Patrick Brunschwig <[email protected]> wrote: >>>>> I am happy to announce Enigmail v2.0.12 for Thunderbird 60.* >>>> >>>>> This release sets the default keyserver to keys.openpgp.org in order to mitigate the SKS Keyserver Network Attack [1]. This change is applied unconditionally for all installations… >>>> >>>> Given that the issue is now mitigated in GPG, when will reverting this back be scheduled? >>> >>> I won't revert this change for two reasons: >>> 2. As I already said publicly, the default in Enigmail 2.1 will be keys.openpgp.org. The change is now just a little earlier than anticipated. >> >> So, just to clarify, you intentionally replaced the standard distributed network with some freshly established private service, where centralized control is _not_ a child illness, but a design: >> >> | Several folks offered to help out by "running a Hagrid server instance". We very much appreciate the offer, but we will probably never have an "open" federation model like SKS, where everyone can run an instance and become part of a "pool". >> — https://keys.openpgp.org/about/faq > > Even though I currently don't have an active role with Hagrid, I am one of its initiators. I'm fully aware of the pros and cons. > > I honestly strongly disagree with the idea that a key directory (and Hagrid is not more than that) must be decentralized. And honestly believe, that it’s fine to break longstanding interoperability between GPG frontends and GPG-compatible programs just because of your personal opinion of how it should be implemented? When to expect an in-house default cipher in Enigmail? > If you want decentralized key distribution/lookup, then use Autocrypt and WKD I beg my pardon, but what a nonsense is that? How WKD is decentralized? WKD for a given address is on a single server, normally controlled by one of the two potential attackers. So in the terms of security it’s even worse than your private service. Anyway, it’s irrelevant for now, WKD vs. HKP is not what we are discussing. And Autocrypt is not a way to publish your key at all, but to send it privately. > Furthermore, you rely on Enigmail, which is developed by me, myself and I -- with very little help from others. That is, many people rely on a centralized system sitting above my shoulders for their encrypted communication. Do you think that's any better or worse than using a centralized directory for key lookup? No, I believe I do not rely on ‘Enigmail centralized system’, only on OpenPGP, which is an open standard, and on SKS, which is a distributed network that until your diversion seemed to be an unanimously accepted standard de-facto; and on some free programs, but it does not matter on which exactly, as long they do not cause any negative network effect. Or do I miss some another nasty feature of Enigmail, that also would have an impact on my correspondents: force them to use some proprietary service, nonfree software, or something like that? Please, do enlighten me on that. >> moreover, pushed that change to setups of the most old users, — and found all of that absolutely okay? > > Given the circumstances - yes. My plan was to set the new default, but to NOT touch the existing installations. But the SKS issue forced me to go that way. That is, you were even going to break seamless interoperability between different installations of your own program initially? o_O >>> 1. It will take weeks to months until the majority of the Windows and macOS systems will have updated (which first requires the availability of new versions of gpg4win, GPGTools, GpgOSX etc). >> >> Well, that’s exactly the kind of answer I hoped to get: a stub will be reverted when such and such updates are published. But I see now, I was too optimistic. :-\ > > This is not a problem that only affects a few dozen users who are savvy enough to handle this, or to look up resources for fixing this. This is something that affects many thousand people, if not more. And it is simply out of question for me to spend my free time on handling the support requests of all these users individually. And this *will* happen. I just had 2 support requests this morning. And so instead of the obvious disabling of HKP lookup at all until things are fixed, you took a DDoS of the present open system as a perfect opportunity to radically promote a new competing proprietary service, “one of whose initiators” you were. Very clever, my sincere admirations to you. > And as I said - I can't undo that because people are too lazy with updating their software. So? What are obstacles to perform a simple check of GPG’s version used? _______________________________________________ enigmail-users mailing list [email protected] To unsubscribe or make changes to your subscription click here: https://admin.hostpoint.ch/mailman/listinfo/enigmail-users_enigmail.net
signature.asc
(application/pgp-signature, 487 B)
-----BEGIN PGP SIGNATURE----- iQEzBAEBCAAdFiEE1yoTx9fONarixgNIydoJ3hnBsjAFAl0nnFUACgkQydoJ3hnB sjD7RQf9HkQRrPYsyT/aRBOsO0aMc3geoz2wykOaV59M/msqEzaq9VwN+ojNFZ5o sMjOAXnsWZwelHNa9dP+n+47tPiZ67JsoerTm1YE2KmKZMvaTBefIRK9LNpwQSg3 4IjkNn2G6F6Pk84c/mebV26ihcEVMhZvvPjYFU2RF3N8LsOIaC5qDwVnlAHnnWlL HC9wz7fVoM8/x0tDlDS9Qk4jFqzt69Ot/QLlkIc2zXi2gfyuKrC8L8NLUbEXoQNm aQTgF53jk4AmelOdLvssmNHZEsdL7WfOdhrYrdKnElslq8LwocDj5IqrIuPt0rIT +lNExrrTEYdhsIFIRPg2M8HhiI+BZw== =Chti -----END PGP SIGNATURE-----