Gilberto wrote:
Mike Easter wrote:
Encrypting email is one thing; clearsigning news msg/s is another.
The reason for clearsigning is so that a reader knows that the msg
was indeed sent by a specific person, and that actually only really
works properly if the proper Web of Trust process is established,
which it is typically not. Usenet is also sometimes a sporgery
haven, but there are better remedies for that than clearsigning.
I read this paragraph, reread it and had it translated by two
artificial intelligences, but to me, the meaning is still unclear.
I'll try again.
You explained that you encrypt your email for privacy. Fine.
My 'argument'/position is that mail encryption is a different subject or position than clearsigning usenet. What you are doing here is
clearsigning your messages.
The purpose of clearsigning a message is to verify that the person who composed and sent the message is the same person who created the public key.
But, in the beginning of pgp, the Web of Trust was very 'direct' in
which people who knew each other assembled in person and exchanged keys
by sufficient identification of each other, by familiarity or adequate credentials.
I'm saying that it serves no purpose here to clearsign your messages,
because those who *might* choose to verify your message here have not collected with you or credentialed you by any form of Web of Trust.
Moreover, it is my 'belief' or theory or opinion that 'almost no one' is equipped with a method to verify your clearsigning.
I chose to dig up your public key ID with a tool pgpdump on your
clearsign. I chose to dig out your public key ID after you tried again
to put it on a keyserver. That was an 'exercise' for me; I don't
normally do any of that.
I argue or opine that it is a small waste of bits to clutter your
message and message header with the autocrypt data and the body clearsign.
I'm also familiar with the argument or opinion that there is value in promoting more encryption to the public. I do agree with that, but I
argue that purpose can be met by JUST including your keyID in your sig,
but not clearsigning. And, you don't even provide your keyID in your sig.
We are very off-topic for Mageia; I don't have that up right now to see
how I would equip it for pgp/gpg; I know about Tb & openpgp; I know
about Claws and its plugin.
--
Mike Easter
--- MBSE BBS v1.1.7.2 (Linux-x86_64)
* Origin: Air Applewood, The Linux Gateway to the UK & Eire (2:250/1@fidonet)