[openpgp] Re: Ideas for alternative user interface terms for OpenPGP structures

Bruce Walzer <[email protected]> Thu, 26 Feb 2026 05:40:55 -0600
Newsgroups gmane.ietf.openpgp
Message-ID <[email protected]>
On Thu, Feb 26, 2026 at 11:37:14AM +0100, Kai Engert wrote:
> Hello,
> 
> this message isn't about protocols, algorithms or packet structures. It's
> just about user interface terms.

I agree that the terms "certificate" or "public key" for the thing
tagged as "PGP PUBLIC KEY" are not all that great. Neither maps to a
preexisting concept in any way that leads to a helpful conceptual
model for the user.

I tend to use the term "PGP identity" for the "PGP PUBLIC KEY" and
"PGP identity number" for the key fingerprint. The idea of mapping
things to human identities is fairly fundamental in most cultures and
these things are all about human identity in practical use.

I think that when choosing terms we have to first think about what a
thing means to the user. What we call the value that identifies a user
in a messaging system is not a problem specific to OpenPGP usage. It
seems that every system comes up with a unique set of terms. So
"safety number" for Signal Messenger. "Security code" for
WhatsApp. This lack of standardization is not helpful to usability.

This lack of standardization of terms extends to the secret value(s)
used to restrict "executive authority" over a identity to a single
user. There doesn't seem to be a really good preexisting concept that
maps here. "Executive authority" is the best I have come up with to
date. It's at least technically accurate and is used in some cultures.

Bruce

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]