4 ms·
Someone generated a public key and caused it to be held by a keyserver by validating it. One would think the onus is on them to limit the validity of what they
by abofh 3y ago
Someone generated a public key and caused it to be held by a keyserver by validating it. One would think the onus is on them to limit the validity of what they want the key used for, not a presupposition that only certain unknown bits of data can be used with this otherwise public and published key.
I publish a key associated with abofh@ycombinator.com - I would expect things that identify me as such would use it. If it identifies me as a phone number, I wouldn't expect it to use it. If it identifies me by my mastadon handle, I wouldn't expect it to use it. This isn't complicated - the author published "use this public key for me@foo.com" - people did (via automated means), and the author found out he wasn't properly equipped to handle that mail. So he withdrew the publication and everything worked normally.
Nothing in here is anything more than "I did something 10 years ago that bit me in the ass today" - which to be fair, happens to all of us, but don't blame the technology for doing _exactly_ what the user asked for even if they forgot they asked.