[openpgp] Re: on discarding Literal Data Packet metadata [ was: Analysis document]
Andrew Gallagher <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <[email protected]> |
On 14 Jul 2025, at 07:25, Falko Strenzke <[email protected]> wrote: > I think the right path would be to first upgrade them to an optional security mechanism (i.e., a hashed subpacket used by the verifier if present). At the same time those fields might be marked as deprecated (requiring that deprecation is supported by the commonly used CLI tools and libraries). I think you make a good point here - a critical subpacket would require choreography (all receivers would have to be upgraded before any producers), and so would not be an opportunistic upgrade. Whereas a non-critical subpacket would be strictly no worse than the status quo. > I think an important question that is underlying these considerations is who is the real OpenPGP user base. I don't think it is just the few F/LOSS email clients, packet managers and backup tools. In my experience, OpenPGP is used in proprietary industry applications. Agreed, we should not expect to ever definitively know who the OpenPGP user base is. Without widespread telemetry, which would go against everything OpenPGP stands for, we rely on self-reporting and membership in groups such as this one. And it’s not reasonable IMO to require that everyone pay attention to IETF WG discussions as the price of having their particular use case supported. That doesn’t mean we should support every obscure corner case forever, in case it breaks some hypothetical workflow somewhere, but reasonably obvious (and low-hanging) cases like this are worth the effort IMO. If there is concrete interest in implementing such a scheme, I would be willing to revive the draft…? A _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]
signature.asc
(application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEKR55odxVrielLu+DXB7EBNWQZikFAmh04voACgkQXB7EBNWQ ZinHpg//ZAFc1kRtE25PheXv6yF26+omiAf9CfnJSFqpBMTHrQfog/QdrFMNYVll QBcHqPiXlN/+APPXt5etmkeqUHzQKURu08tnyZb2Q/cBqmQoxfu16CvaUssOiI3l B1DdrRhfdlSYvLEQAZdpaw9bwAkpaB2cJlAf0y98VxRkP5b7gna2nR7etOjW3QiT zZCDI1y9oZph9JNINT16VlSYYGgXRYhAN9ZrAdHzQWzx+sxQfoF+McqGFLwvLqeZ XiP+RJTtHhXbnlMstiWGPrG8b1Kmi3exm0L4N87E5OIpMrQdSF3jPW0ylvyrusWS 6qESRDNfXm4WikIXqnYM7oTMFLQ1qjQDJ79s8BHk1FKJi8g7j7uilx1I0Zs6iel2 qVxNLHzjr2xL2UPJsGK6LEkAkdrfykhAR4e8FJ3Tw02eN5rPbp7Qk5Om8mk/QjZJ 21v/8wQ/mORsF9oDapU54kNYeL0+sapQSv3YLt287pCX3b2xpXU2d4CHIjEZju5G THOFyddT2wVfeVBBPZLIcX9/c1bheHOA0zKM/Vp5GNRFrMlUqcwaaRKeHpyupipR IjGrfMaCGT7WcOQ5kiECKLY3l/P7h4/Svuye0S2Ts4/YWyqXORXHrtR1S/pyBHN1 0QW6JbcIBp9b8rx6DOhLaDjGD/GbEk4mE72VyKrZvsDSyd3LNcw= =cA5n -----END PGP SIGNATURE-----