[openpgp] Re: Certificate discovery over HKP

Andrew Gallagher <[email protected]>
Newsgroups gmane.ietf.openpgp
Message-ID <[email protected]>
On 9 Apr 2025, at 10:40, Daniel Huigens <[email protected]> wrote:
> 
> So the only difference here is that the attack is silent also for the
> sender, in the sense that they will still see that the message will be
> encrypted, if they trust the keyserver. Perhaps that's still significant
> in the sense that they might be more willing to send sensitive data in
> an encrypted email (but then again, you could argue that in that case
> they should verify the key first).

Agreed, but we’ve spent enough time telling people to look for lock icons that a significant number of them will behave differently when the lock icon appears - in which case we’re giving them a false sense of security. Sure, they *should* verify out of band, but how many will in practice?

And I do appreciate that the same argument applies to DANE etc. over DNS-non-SEC. But it's a regression when compared to WKD over TLS.

A

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEKR55odxVrielLu+DXB7EBNWQZikFAmf2RFwACgkQXB7EBNWQ
Zimvlw//VLVdYIAmqwqerFjY2zS4xWD9o5QTVWq3zGvNFlTd7umOzb6c6QnJQhJ8
J1ODtOIa3uKv2TyabsFPd3FTDKhtTXj334q34jhta12ba6hSjyIavLkJstf+6sI8
jfVROvJWFwqIU+fyqxGHzQG6/glWe6lAGP8mABRi4uNkIiEKYDJaoWSggolQdIZT
5JMNWGyNRt2b+Bvc9bd3jFXISqWIqGN0/jCUoJ7Yxbf0Dquh9iehQaO9y7SHwpKA
hMx6wNerXb9AVQ2k/y020hbDwNmKuiMlr0xlCC1bEtI4UYOUm9LUJgQQh7xZAKpk
SUfUZ5OGv177F0WB3WRvxePG+SRvdoO2dvGfKRwTog2UxBc967A56Z0g8UNLSb76
Atogep5z2pbjGZtVqc9UEtRdXdPfWxkSeyb8m7oqKDsLGe2yJvjj6EaJd+SF+A3u
YhpTYhJGzvnWHKgs6llBj67QSg1wUV+F/S35voP3Oh/nWKt6ZlXoWLH4tgUQwxOe
hFADGdbTv6CkUcHZgf5pRQu87MB0KxCWliHlxdyQ23/2D8TZdcTX1UwoOAlYFj31
fbO1ZxwP++NOz9L5bdmB8aZR2OCM+iPkH1f97FWoQya6XNb7vNhZ8UgbxF4sXgHn
lmBCD1gQIAJ834xUbbRWcp/haN/zGEnWh4/JQw9RpinBtwwWO3Q=
=/Qt/
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.