[messaging] Advertising public key in email (was: TOFU to ease PGP key discovery)

Mike Hearn mike at plan99.net
Wed Feb 11 02:46:54 PST 2015


>
> it's too transparent, though - I can't tell what's encrypted or view
> fingerprints


The UI for this is terrible, but if you click the little tick symbol next
to "Signed" then it will open a certificate viewer and you can see the
certificate+fingerprint used to sign. There is no indication that this
black and white icon is clickable, but it is.

Thunderbird appears to just be buggy. Their integrated crypto/signing
support appears to have been unmaintained for years, judging from bugzilla.
You shouldn't be able to send a mail that's encrypted but not signed, that
makes little sense.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://moderncrypto.org/mail-archive/messaging/attachments/20150211/eedc0495/attachment.html>


More information about the Messaging mailing list