ietf-openpgp
[Top] [All Lists]

Re: MIME media type literal packet in OpenPGP

2011-03-11 15:37:29
On 03/11/2011 07:39 PM, Vinnie Moscaritolo wrote:
* PGP Signed: 03/11/2011 at 10:39:52 AM
Greating;

I just posted an informational draft about some minor changes that the
PGP sdk
is now supporting.   comments and complaints are welcome.

Hello,

I have two complaints about this proposal:

1. There is an already widely used way of encapsulating MIME content
into PGP messages, PGP/MIME (a.k.a. RFC 3156), and this proposal is not
compatible with it.

2. In this proposal, mime type would not be part of the hashed content
for digital signatures, meaning that it can be changed without breaking
the digital signature. This is dangerous. PGP/MIME does not have this
weakness.

-- 
Daniel

Attachment: signature.asc
Description: OpenPGP digital signature

<Prev in Thread] Current Thread [Next in Thread>