[openpgp] Re: on discarding Literal Data Packet metadata [ was: Analysis document]
Daniel Kahn Gillmor <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <[email protected]> |
On Thu 2025-07-10 15:58:02 +0100, Andrew Gallagher wrote:
> it is intended to provide a drop-in replacement for those workflows
> that currently rely on them.
Can you (or anyone following this discussion) identify such a workflow?
I'm asking literally, not rhetorically. We should be developing the
protocol based on at least reasonably well-understood use cases.
I'd like to know who is using this workflow, because that application is
by definition already broken, and needs to be fixed. If it's F/LOSS,
I'd like to fix it. It can't be fixed at the OpenPGP layer, unless the
OpenPGP tooling used by the application were willing to suddenly break
all *existing* OpenPGP messages, which we know don't have this
protection.
Given that the application layer work will need to be done to fix
legitimate use cases anyway, i don't see the point in re-inscribing
dubious decisions made over three decades ago (these fields are in RFC
1991 which was informational about already-deployed code back in 1996).
What metadata is necessary for a specific use case might vary based on
the use case. Let's try to build from actual needs, and just drop
legacy stuff that we know doesn't work, rather than trying to cobble
together a fix for a feature that is known-broken for many years.
--dkg
_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]