3 ms·
> (ie, fetching keys from keyservers, encrypting automatically, etc) No no no no no! The keyservers have no authentication for key addition. Anybody can put
by FedRegister 13y ago
> (ie, fetching keys from keyservers, encrypting automatically, etc)
No no no no no! The keyservers have no authentication for key addition. Anybody can put up a key for any email address and effectively wedge themselves man in the middle.
- bigiain 13y agoAlso, the paranoid in me (and probably more significantly, the keyboard-activist-in-the-safety-of-my-parents-basement) suggests that it might be wise to access keyservers over TOR. If _I_ were involved with PRISM, the pipe running to pgp.mit.edu would be one of the most monitored connections around. "Hmmm, someone just searched for a PGP key for FedRegister - lets see what else that IP address has searched for, and what's in all the gmail inboxes that have ever been accessed using that IP address…"
- grabhive 13y agoYes. This is the way that hackers should be thinking from now on.
- chimeracoder 13y agofacepalm Yes, I redact my above comment to remove that example. However, I still stand by my statement that PGP UX is a client issue, not an inherent protocol issue (ie, it's fixable without abandoning PGP entirely).