6 ms·
No, Proton didn't assume WKD was activated, and WKD doesn't have much to do with what's going on. What happened is: - The user, or their software, uploaded a p
by twiss 2y ago
No, Proton didn't assume WKD was activated, and WKD doesn't have much to do with what's going on. What happened is:
- The user, or their software, uploaded a public key to keys.openpgp.org
- Proton looked up their email address on keys.openpgp.org, and sent them an encrypted email
- They didn't have the private key anymore, and couldn't read the email
The fix is to remove the key from keys.openpgp.org, or remove the email address from the key, or remove the encryption subkey.
Alternatively, setting up WKD would actually work as well, since then Proton uses that instead. I.e. if there's no key on WKD, we don't send encrypted emails.
- rakoo 2y agoWhy does proton look up keys.openpgp.org? Is keys.openpgp.org assumed to be The One Directory for everyone ? Who said so ? There is no reason to consider it as the centre of the world if you deon't use it. That's exactly what wkd is about: specifically saying that there is a key to talk to you, and where it is. If I publish a key in my Myspace profile that doesn't mean it's valid. The author never signalled any key to be usable, the key being on that specific directory means nothing. It's not the first time you take liberties with protocols and specs under the premise of "simplification", and again ano again things break because you don't respect anything. How can you be taken as a peer of value if you keep screwing up and accusing users for not holding it right ?
- twiss 2y agokeys.openpgp.org is the semi-canonical key server for OpenPGP. Certainly there are other key servers, but it makes more sense for us to look up keys on a keyserver hosted under openpgp.org than one hosted by Ubuntu or any other single entity. KOO is a community-led and -governed project. It now even has elections and a board (which we joined): https://keys.openpgp.org/about/news#2023-04-28-governance https://keys.openpgp.org/about/news#2023-04-28-governance WKD is great, but can't be used by people with email addresses under domains that don't support it. So KOO fills that gap.
- rakoo 2y agoYes, KOO is a good intermediary, but it still matters: there are no agreed-upon mechanism saying it should be used in all cases. You took this liberty. Why not even ask the receivers, aka those who know, if they're ok using that key ?
- twiss 2y agoWe can't easily ask them that. KOO could ask, though, since that's what the user's interacting with when they're uploading the key. And, I do agree that the signalling could be improved, there, so I'll discuss it with them.