Re: [gmime-devel] pgp inline encrypt/decrypt support




Correct, I care for signing and verification too.

I am aware of the issues surrounding inline pgp but I receive many
emails under this format and apart from letting people know that this is
wrong, I need to finally read the email. It is too much of manual work
to finally read the email, so I'd appreciate it if this could be done
automatically through gmime/mu. Of course I'll keep telling people to
stop using inline pgp.

Daniel Kahn Gillmor <dkg fifthhorseman net> writes:

On 10/28/2014 10:44 AM, Dan Milon wrote:

I'd like to see support for PGP inline in gmime which will then be used
by mu (https://github.com/djcb/mu).

your subject line says "pgp inline encrypt/decrypt support", but the
sentence above suggests that you might also care about cleartext inline
signatures as well as verification.  These are distinct problems, in
terms of both message integrity/legibility and UI/UX.

In practice, inline PGP presents some fairly difficult challenges for
people who care about robust message handling.  in particular, you might
want to read:

 http://josefsson.org/inline-openpgp-considered-harmful.html
 https://dkg.fifthhorseman.net/notes/inline-pgp-harmful/

and make sure you understand the concerns listed there before you head
down this path.

      --dkg

Attachment: signature.asc
Description: PGP signature



[Date Prev][Date Next]   [Thread Prev][Thread Next]   [Thread Index] [Date Index] [Author Index]