[openpgp] Re: Proposal: Provider-assisted OpenPGP key disc overy
Michael Richardson <[email protected]> Wed, 15 Jul 2026 21:26:29 +0200
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <359992.1784143589@dyas> |
--===============6796500954321780173== Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha512; protocol="application/pgp-signature" --=-=-= Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Daniel Kahn Gillmor <[email protected]> wrote: > On Wed 2026-07-15 10:22:37 +0000, Bart Butler wrote: >> I will point out that getting the major ESPs to use such a registry >> will absolutely never happen. > Presumably Bart's description of "major e-mail service providers > (ESPs)" refers to Microsoft and Google, but not to Proton itself. =E2= =98=BA > It's entirely possible that users whose e-mail addresses are controll= ed > by these major platforms will be unable to make use of the kind of > automated OpenPGP certificate discovery you're contemplating, due to > recalcitrance of their ESP. Yeah. If one could get three of (proton, fastmail, tuta, zoho, mailbox) to implement, I think it would be a win. Someone on google or outlook can still just generate a key and bring it to some keysigning party. I'm rather unclear why the "endorsement" that was in the first email is different than a regular openpgp signature... I used sign stuff from [email protected]. > I think the question for the WG is whether it is sufficient to build a > mechanism that works for users *not* in that group, given that the WG > has no control over the business decisions of these entities. > From my perspective, it seems reasonable to do that kind of work, as > long as we're realistic about the reach. The goal for e-mail is a > functioning federated system. +1. =2D- Michael Richardson <[email protected]>, Sandelman Software Works -=3D IPv6 IoT consulting =3D- *I*LIKE*TRAINS* --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQEzBAEBCgAdFiEERK+9HEcJHTJ9UqTMlUzhVv38QpAFAmpX3uUACgkQlUzhVv38 QpC3dAf/fO6nW51vLNnKOo9ZazezaIo9myyqLs3h8lXDNA8AkJlZuPRwDrxVQNG1 af+8w15N/vNbON4Ig6c7WLnEGNmb2TyoaHrQ6riibgwek04SstutYdpQMYoTjg+H ld81u9X3dHrLBBKr5c8u9rnKTCP1xsySvRkhWEZIGOIXMeIlrvKp67u1WwT+qLEq Lqfyml7gADnu3G+kUY/HCwdNtRNpbRewkKFUXjNNIHt+h2tPBZPuLKtqzi13AmX/ rUU1ENEXtcL4SuLSUkUxV/Y/d9UOaA8u1CnnjB53r+sC2ne3azHUfmOwcelNWPLx ty0PZJi0vz0cJhcOzknNwcwBQ6Q45Q== =ltC0 -----END PGP SIGNATURE----- --=-=-=-- --===============6796500954321780173== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18Kb3BlbnBncCBt YWlsaW5nIGxpc3QgLS0gb3BlbnBncEBpZXRmLm9yZwpUbyB1bnN1YnNjcmliZSBzZW5kIGFuIGVt YWlsIHRvIG9wZW5wZ3AtbGVhdmVAaWV0Zi5vcmcK --===============6796500954321780173==--