8 ms·
If I didn’t want people to encrypt mail to my pgp key I would simply not upload it to a public pgp key directory. Honestly, what is the complaint here? If you
by eduction 2y ago
If I didn’t want people to encrypt mail to my pgp key I would simply not upload it to a public pgp key directory.
Honestly, what is the complaint here? If you don’t want people to use certain contact info don’t put it on the open internet.
To get your key in that key server not only do you have to submit it you have to verify it via email. It’s literally… to spread it widely… to anyone who wants it… so they can send you encrypted mail. That’s the entire purpose of the thing.
Like if i put my phone number on a billboard I have no right to complain when I get calls.
Take responsibility for your actions.
“ However long we postpone it, we eventually lie down alone in that notoriously un- comfortable bed, the one we make ourselves. Whether or not we sleep in it depends, of course, on whether or not we respect ourselves.” Joan Didion https://www.vogue.com/article/joan-didion-self-respect-essay-1961 https://www.vogue.com/article/joan-didion-self-respect-essay...
- worddepress 2y agoMore charitable is that the user thought it would do X and it ended up doing Y. They may have even been happy with X even, if they knew that was going to happen, because the whole thing would have been less confusing. > I'm at a little bit of a loss here. I totally understand sending me encrypted emails if I've gone through the steps to set the CNAME that indicates that I want to do that, but it doesn't seem like that's how the service works. As far as I can tell, the act of uploading a OpenPGP-compatible key seems to trigger their service to send it as an end-to-end encrypted message. A similar example is how Windows changed their OS to require a PIN, which can be a password if you figure how to. It then asks you for this when doing completely unrelated to your OS online stuff sometimes, like some of the weird flows to do with using Teams or whatever, and I am not expecting it was asking me for my PC pin because it before that just asked me for my Online username. It is a UX issue.
- jrockway 2y agoI don't know... I thought encrypted emails were cool in like 2002, so I probably have a key on a keyserver. I probably lost the ability to revoke that key, and simply stopped caring after not receiving a single encrypted email in 25 years. So I would be very surprised if someone sent me an encrypted email today. (I actually do know where my key material is. It's on a smartcard that nothing that exists today can read. Back in the day laptops had smartcard ports! Crazy.)
- napoleongl 2y agoThe one feature of an HP Elitebook that could perhaps be called ”Elite” is that they come with smart card readers built in. USB-readers also exist.
- vladvasiliu 2y agoNot all of them. Some models don't support them at all, others only have it as an option. My EB845G8 has the slot, but there's no reader inside.
- stingraycharles 2y agoI also don't have access to that private key anymore anyway, but I'm still using the same email address.
- layer8 2y agoWhat is indeed missing is a limited validity period of the key, as a certificate would provide. Then everybody would be clear on how long the key can be used.
- c0l0 2y agoOpenPGP Keys do have expiration dates/validity periods: https://datatracker.ietf.org/doc/html/rfc4880#section-5.2.3.6 https://datatracker.ietf.org/doc/html/rfc4880#section-5.2.3....
- yau8edq12i 2y agoThe good thing about GDPR is that these keyservers must delete your info after some time unless you periodically renew your consent.
- TylerE 2y agoGood thing every company and web server on the planet is in the EU! How else would 10 people make lazy GDPR posts on everything vaguely related?
- kelnos 2y agoBecause PGP keys are used for more than just encrypting email. I mostly only use mine to sign release tags for software I publish. Having that key uploaded to a public keyserver is a useful thing to do in that case. But maybe I wanted to use it for other things... perhaps I just want to sign my email, and not encrypt what I send, and allow others to verify the signature. Having the key out on a public keyserver is essential for that. Honestly I don't know why acting so rudely about this, to the point of pretentiously quoting a famous author/journalist. Not to mention the fact that you haven't thought through all the various reasons why someone might have a key published. Maybe step back from the keyboard and breathe a bit?
- Freak_NL 2y agoExactly. My key is on there because we have a shared password-store synched in a private git repo encrypted with the keys of select number of colleagues for some work credentials and keys. It is useful to be able to find each other's keys automatically based on the key fingerprint. I can probably read e-mail encrypted with it just fine as long as I use Thunderbird with my Fastmail inbox (which is most of the time), but not when using K9 Mail on a smartphone or the web UI of Fastmail.
- soraminazuki 2y agoThat's not what public keyservers are for. You're free to use it any other way, but it's unreasonable to shame people who used the keys you advertised in a way that matches general expectations. Besides, it doesn't make sense to upload keys only meant to be shared among a small number of people to a public keyserver. In your case, the keys better belong in the git repo.
- caddy 2y agoI feel like that defeats the purpose of the validation. If you're storing the keys in the same place as the code, it would be very easy if someone gained malicious access to the repo to change the key and sign it with the new key.
- pflenker 2y agoNeither the sender nor the recipient made an active decision that the respective mail should be encrypted with pgp. That’s the issue here.
- deely3 2y agoThey uploaded PGP key to open directory and then verified email, what is this as not an active decision?
- franga2000 2y agoIt's an active decision to make their key available to people who wish to send them encrypted email. It's not a decision to receive all email in encrypted form.
- deely3 2y agoIm not sure that I see logic here..
- nkrisc 2y ago> It's not a decision to receive all email in encrypted form. Except, it is. You can’t control of everyone out only some will send you encrypted email.
- lxgr 2y agoI mean, sure, if somebody wants to take a guess on whether I have my private key with me (or even still have access to it at all), that's on them. But if an email provider purportedly bringing email encryption to the non-GPG-trained masses does, it's a different story.
- PKop 2y agoUsing Proton for email means it is. Why use Proton otherwise?
- arghwhat 2y ago
- tedunangst 2y agoEven if I published a public key, I wouldn't keep the private key on every device, and if I have to dig out my yubikey just to find out you're in town for lunch next Tuesday, we're probably not having lunch.
- reidrac 2y agoYes, this is true. I never felt comfortable having my private key on my phone, so I can't read encrypted email on the go. I get one or two encrypted emails on a good year, and they are rarely important (or require encryption really).
- gwd 2y ago> I get one or two encrypted emails on a good year, and they are rarely important (or require encryption really). Well if only "important" things are encrypted, then the existence of an encrypted message is evidence to whomever you may be trying to hide from that something "important" is going on. Ideally everything would be encrypted, important or not; having all current encrypted things being unimportant is actually better than having only important things encrypted. :-)
- reidrac 2y agoMy point was that those emails can wait until I'm on my desktop and I can decrypt them. I should have used "urgency" instead.
- Andrex 2y agoI also have a fear of having my private key on my phone, but it's a nebulous kind of paranoid fear. I don't know if there's actually any good reason to have this paranoia or what the best practice is. I suppose having the same key in fewer places inherently increases security, but there has to be a line somewhere... Not accessing email on my phone would be a giant productivity killer.
- dimask 2y agoActually it seems like a feature to me (to be able to exchange encrypted emails so easily between different providers), and a quite nice one actually.
- Macha 2y ago> If I didn’t want people to encrypt mail to my pgp key I would simply not upload it to a public pgp key directory. I have keys uploaded to PGP directories that I have in the past used for Git commits, and use today for linux package signing. I've never used encrypted email, so it would be surprising for people to try use it to send email.
- upofadown 2y agoMy understanding from the article is that correspondents are not encrypting the mail, but that Protonmail is. So unencrypted messages from Fastmail are being encrypted to a key that Protonmail found on a random keyserver when that email hits the Protonmail server. This is a common feature provided by privacy oriented email providers. The idea is that the provider will only have access to the unencrypted email at entry to the server but not after that. The email of course can't be signed in any meaningful way, but the original unencrypted message wasn't signed either. This strikes me as the sort of thing that you would want the user to specify a particular key for, but I suppose Protonmail is attempting to increase usability by making it as automatic as possible.