13 ms·
I actually like this behavior ... If you have a key, use it!
by smoyer 3y ago
I actually like this behavior ... If you have a key, use it!
- kiwijamo 3y agoThe OP doesn't recall generating one. Genuine question: do you also like it when someone else generates a key for you without telling you? Personally I would rather know about it.
- int_19h 3y agoThe OP did generate one and placed it in a public registry. What they didn't do was indicate that this key should be used to encrypt email sent to them to them.
- abofh 3y agoThey published it with an precise link to their email address - what were people supposed to conclude from them publishing it - "never use this pgp key unless you've spoken to me in person?" - that... kinda defeats the whole point of publishing a key _and_ the handle by which it's looked up in the same database. If you didn't want that, you'd associate it with something else that wouldn't expect encrypted email - like a name or a GUID and point people there when they need it. They wrote in the book "me@foo.com: use key" - and then people did. If he wanted different behaviour, he could have published "someoneelse@foo.com" and then they wouldn't use it to email _him_.
- PeterisP 3y agoIn the current world an "email address" is not solely (or sometimes even primarily) for delivering email, but rather an identity or username for various systems, such as for signing git commits. So a key linked to an identity (email address) does not imply in any way that this key is also used or usable for encrypted communication.
- kelnos 3y ago> "never use this pgp key unless you've spoken to me in person?" Well, yes, actually, that is what I would expect. (Well, not necessarily in person, but via a different communication channel, even by unencrypted email.) I remember when I was first playing around with PGP more than 20 years ago. The usual convention was to talk to the other party first about encrypting your messages, and not to assume that the recipient could receive and decrypt them in all circumstances.
- lxgr 3y agoThe original PGP idea was a "web of trust", which meant doing key signing parties and you hopefully ending up with a transitive chain of trust to anybody you might want to contact. Just blindly downloading keys from a keyserver and hoping they're the real thing was not the idea.
- Arnavion 3y agoRight, but other than the bug, the feature does seem nice. I do use WKD, and although nobody has ever sent me PGP email, it's nice to know that ProtonMail users would find it convenient to do so.
- lxgr 3y agoIt’s an absolute no-go. I do have an OpenPGP key published to the key servers, mostly for toying around with GnuPG cards, but as soon as anyone starts emailing me encrypted messages without any context, I’ll delete it.
- unethical_ban 3y agoI don't understand. It's not a security risk to read an encrypted message. Why would you delete an encrypted message?
- mkl 3y agoDelete the key off the server, I think, not the message.
- lxgr 3y agoYep, that’s what I meant!
- unethical_ban 3y agoStill strange, but I know what they mean now.
- lxgr 3y agoAbsolutely not without a flag on the key that indicates “encrypt email to this key by default”, or at least the domain admin having explicitly pointed WKD to the public key servers.
- nulbyte 3y agoThis is such a bizarre take to me. If you don't want people using your key to encrypt email to you, why are you uploading your key to a service designed to help people find it to encrypt email to you?
- cl3misch 3y agoTo play around with it?
- jraph 3y ago> to encrypt email to you this part is incorrect: keys have other uses. It's not because you sign Debian packages that you encrypt your emails. With the same key. Hence the need to have a way to say "this key is for encrypting emails with such method and such protocol".
- soraminazuki 3y agoThen only upload a signing key. Don't upload encryption keys. PGP is capable of making that distinction.
- erinaceousjones 3y agoYes, but how many other things can you think of other than email which you would share your encryption public keys for? Honestly email would be at the bottom of applications I would think of, even when registering keys with a key server. If you have a bunch for different use cases (or like, levels of security/secrecy/revoking-this-will-be-a-nightmare), which you've set your one email address as recipient for, which of those is "default"? The keyserver and protonmail also are entirely separate. I wouldn't expect the two entities to be communicating with each other if I hadn't opted in. It feels weird, like when private companies harvest your data without asking.
- pmontra 3y agoFor every single use case a key can be used for? Automatically? Maybe even for use cases that didn't exist when the key was added? (Email did exist)
- abofh 3y agoSomeone generated a public key and caused it to be held by a keyserver by validating it. One would think the onus is on them to limit the validity of what they want the key used for, not a presupposition that only certain unknown bits of data can be used with this otherwise public and published key. I publish a key associated with abofh@ycombinator.com - I would expect things that identify me as such would use it. If it identifies me as a phone number, I wouldn't expect it to use it. If it identifies me by my mastadon handle, I wouldn't expect it to use it. This isn't complicated - the author published "use this public key for me@foo.com" - people did (via automated means), and the author found out he wasn't properly equipped to handle that mail. So he withdrew the publication and everything worked normally. Nothing in here is anything more than "I did something 10 years ago that bit me in the ass today" - which to be fair, happens to all of us, but don't blame the technology for doing _exactly_ what the user asked for even if they forgot they asked.