[openpgp] Re: New Version Notification for draft-gallagher-e mail-unobtrusive-signatures-00.txt

Andrew Gallagher <[email protected]>
Newsgroups gmane.ietf.openpgp
Message-ID <[email protected]>
On 14 May 2025, at 11:09, Stephen Farrell <[email protected]> wrote:
> 
> DKIM2 is also proposing an algorithm to "unwind" some of the
> changes that may occur to mail in transit (e.g. mailing list
> footers) so one can validate a signature from before those
> changes were made. If we create new mails with multipart/mixed
> those might interact with that still-being-developed algorithm.

So long as the message that is end-to-end-signed is the same one that gets signed by the first DKIM signer (i.e. the sender’s mail provider), then any subsequent changes and/or reversions in transit should break (or fix) both the DKIM and the E2E signature equally - which would also be the case for traditional PGP/MIME signatures.

The only caveat is whether DKIM’s relaxed/relaxed canonicalisation allows a DKIM signature over a slightly mangled message (e.g. trailing whitespace) to validate when an E2E signature would not - but the message canonicalisation guidance in section 5.4 of the current draft is designed to avoid this.

>> I personally feel some pain from people not understanding 'signature.asc'
>> attachments, but not a huge amount.
> 
> Ditto. Though it does "break" things when people say they
> can't read your signed emails because of that, so it is a
> real issue.

Personally, I don’t get many such complaints either. I hadn’t had one in a long time, but a few weeks ago I had a contractor complain because he was expecting me to send him some documents and was trying to unzip the signature attachment. I sent him the real documents and left it at that, but that was because I accepted the consequences when I enabled email signatures; someone who did not make such an informed choice might not be so accepting. We should always keep in mind the difference in practical outcomes between users making config changes that may cause breakage on an individual scale, and software making a change to the defaults that may cause breakage on a mass scale. Pain points that are tolerable in the first scenario would not be tolerable in the second.

A

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEKR55odxVrielLu+DXB7EBNWQZikFAmgkmQ8ACgkQXB7EBNWQ
Zimmtw//cMatWpeRcszEVWlGq4t0DGXidEvmtYKt+jX5aP2scs9aAq4H6PYC04DM
uFJ358OSCDmYKyHMnBmaFlDMeQPbeBRGMboCDLgqcKD4QoCikDq/BPIZOEp2ymbx
1TCXPW9fi4i/GVhdgtdzTU8fh4T04AVqmphY6L/wynQd+rm2pHsrUvP3dVDKLTK/
5OvECDwacD/7enpETQpQvVuyuPWtgGnfm+OOKu+BTqWurL+w21D6jzLuYwlR9wKY
WYuFFXTULAimx31+r++s9NtlAWCbw95Jzvc1lrPtr4wllewS8LdTxkPKOo9WY9IM
jsSdC7ZlTXMaSi8BkmYAzNe3cUVDgtk/u7bGPipQMRVPotPk0ynwHwhSdWvCZ1ij
FS81E5e3BALD8aSOHyI0kGNidj1BniSsws7wJidEb5llsEJ2eYQfCgDLvcODTf2i
FbcJY8KTIUd9hP5jUMT/Zy7LytnE5goWQrVoVhOzpkJpK5A408S+6nUYc89hG0Q3
5pOlO+14V5WpWSvRVfZUpXKNR2BgMD4AXzzvZlP5ykCCnwCFjqHBu2xF7Hj75xrD
seGZY+k1EJATvodXa4F5Mie9Z1R5a9e9g7mqvyDAAdZi5HQUn21HMyH0JI+TE329
+PeETN/JlLt71f26o/3DF4S+MWgdvGdYkSAjVKF2SmvWuZE0pNc=
=37s/
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.