[openpgp] Re: Ideas for alternative user interface terms for OpenPGP structures

[email protected] Thu, 26 Feb 2026 12:28:29 -0800
Newsgroups gmane.ietf.openpgp
Message-ID <[email protected]>
> On Feb 26, 2026, at 02:37, Kai Engert <[email protected]> wrote:
> 
> Hello,
> 
> this message isn't about protocols, algorithms or packet structures. It's just about user interface terms.

Since I am an old perpetrator and have historic context, I thought I'd leap in.

Getting to the bottom line, I think that MCP is not going to be adopted, no matter what. The LLM people already got that, and no matter how good a term it might be, it's just a bad idea to collide acronyms like that. I have other complaints, but I'll push those aside for now because the operational reality of that particular acronym means even with the best intentions, it's going to fail. The first time someone uses OpenPGP in their LLM work, someone's going to say, "hold on, which MCP do you mean: the protocol or PGP keys?" and then they'll just call them PGP keys because that's what everyone has done for thirty-five years. The first time someone is talking only about OpenPGP and a newcomer comes in and asks, "hold on, how does OpenPGP MCP relate to LLMs?" then again, they'll just go back to calling them PGP keys. It doesn't matter if it's a good term or not, it'll end up a footnote at best while everyone keeps calling them "keys."

Now for the historical commentary. Back when we were starting up the original working group for RFC 2440, this debate went on. I was on the side of calling them "certificates" because it's a more technically precise term. Other related systems use "certificate" as well. A certificate is a data structure that contains public key, some metadata that describes that public key, and a binding signature that packages the whole thing up. If the binding signature is the public key itself, it's called "self-signed," and so on. You note that X.509 uses it, and so does SSH these days, and back then it was relevant that SPKI did, too. Nonetheless, "certificate" is the technically precise term.

We got the term "key" because way back in 1991, Whit Diffie suggested it to Phil Zimmermann. The argument for "key" as opposed to "certificate" is precisely a user experience argument, perhaps not unlike the one you make. The word "key" is short. It's short in most languages, too. It's also intuitive. The average person can easily come up to speed when we talk about "key" as opposed to "certificate" -- a four-syllable, abstract term that is precise because it's abstract; it doesn't carry baggage with it. "Key" does have baggage, and that baggage makes it less precise but more accurate. People know what you mean.

On the other side of the debate, an OpenPGP key is not just a key it's exactly what I described above as a certificate. Worse, it's perhaps even more precise to note that it is a collection of certificates once you have multiple subkeys for various purposes. We could even well-actually this and note that it's a collection of *certifications* rather than certificates (and people did).

And yet -- the argument in favor of "key," that it is short, intuitive, and easy to wrap one's head around won the day. We call them keys, and we call them keys because it's good user experience. Despite being supportive of "certificate," it's what people call the darn things, and every time I typed out "certificate" a little voice sniggered in the back of my head telling me I could have just typed "key" and it would be easier.

From an IETF perspective, the term "key" has consensus that goes way beyond rough consensus, more like sanded down, polished, and a nice layer of clear coat on top. 

That decision is of course not without consequences. As I am sure you know -- heck, it's probably the reason you are thinking of alternate terms -- by calling the darned thing a "key" we have to in the details talk about the actual mathematical cryptographic key as Key Material, and once we get into the internal signatures there's a whole lot of talk about "certifications" that are vestiges of the whole debate. The whole reason we have that debate, though, is that at the end of the day, "key" is a pretty good term, and what are we here if not pretty good.

If you want to change the term, the change needs to follow user experience and human factors. The alternate term needs to be short, intuitive, and evocative. Acronyms and initialisms are not really going to work well -- unless they spell out some short, intuitive, and evocative work, and then you don't need an acronym, just use the word. The alternate term has to grab people; the reflex reaction a person has the first time they hear it has to be a positive experience. You need to get people to use the new term on their own, and once it becomes popular, it will take over from "key" all on its own. I don't think that's going to happen (I've tried to think of alternates) because "key" is an established term that has good UX.

Until then, we have to suffer the word "key." We have to suffer it because Whit was right, and for all the problems with it, it's a pretty good term.

	Jon


_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]