[openpgp] Re: on discarding Literal Data Packet metadata [ was: Analysis document]

Andrew Gallagher <[email protected]>
Newsgroups gmane.ietf.openpgp
Message-ID <[email protected]>
On 14 Jul 2025, at 07:25, Falko Strenzke <[email protected]> wrote:
> I think the right path would be to first upgrade them to an optional security mechanism (i.e., a hashed subpacket used by the verifier if present). At the same time those fields might be marked as deprecated (requiring that deprecation is supported by the commonly used CLI tools and libraries).

I think you make a good point here - a critical subpacket would require choreography (all receivers would have to be upgraded before any producers), and so would not be an opportunistic upgrade. Whereas a non-critical subpacket would be strictly no worse than the status quo.

> I think an important question that is underlying these considerations is who is the real OpenPGP user base. I don't think it is just the few F/LOSS email clients, packet managers and backup tools. In my experience, OpenPGP is used in proprietary industry applications.

Agreed, we should not expect to ever definitively know who the OpenPGP user base is. Without widespread telemetry, which would go against everything OpenPGP stands for, we rely on self-reporting and membership in groups such as this one. And it’s not reasonable IMO to require that everyone pay attention to IETF WG discussions as the price of having their particular use case supported. That doesn’t mean we should support every obscure corner case forever, in case it breaks some hypothetical workflow somewhere, but reasonably obvious (and low-hanging) cases like this are worth the effort IMO.

If there is concrete interest in implementing such a scheme, I would be willing to revive the draft…?

A

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEKR55odxVrielLu+DXB7EBNWQZikFAmh04voACgkQXB7EBNWQ
ZinHpg//ZAFc1kRtE25PheXv6yF26+omiAf9CfnJSFqpBMTHrQfog/QdrFMNYVll
QBcHqPiXlN/+APPXt5etmkeqUHzQKURu08tnyZb2Q/cBqmQoxfu16CvaUssOiI3l
B1DdrRhfdlSYvLEQAZdpaw9bwAkpaB2cJlAf0y98VxRkP5b7gna2nR7etOjW3QiT
zZCDI1y9oZph9JNINT16VlSYYGgXRYhAN9ZrAdHzQWzx+sxQfoF+McqGFLwvLqeZ
XiP+RJTtHhXbnlMstiWGPrG8b1Kmi3exm0L4N87E5OIpMrQdSF3jPW0ylvyrusWS
6qESRDNfXm4WikIXqnYM7oTMFLQ1qjQDJ79s8BHk1FKJi8g7j7uilx1I0Zs6iel2
qVxNLHzjr2xL2UPJsGK6LEkAkdrfykhAR4e8FJ3Tw02eN5rPbp7Qk5Om8mk/QjZJ
21v/8wQ/mORsF9oDapU54kNYeL0+sapQSv3YLt287pCX3b2xpXU2d4CHIjEZju5G
THOFyddT2wVfeVBBPZLIcX9/c1bheHOA0zKM/Vp5GNRFrMlUqcwaaRKeHpyupipR
IjGrfMaCGT7WcOQ5kiECKLY3l/P7h4/Svuye0S2Ts4/YWyqXORXHrtR1S/pyBHN1
0QW6JbcIBp9b8rx6DOhLaDjGD/GbEk4mE72VyKrZvsDSyd3LNcw=
=cA5n
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.