ietf-openpgp
[Top] [All Lists]

Re: About User-ID's

2001-08-20 08:09:46

-----BEGIN PGP SIGNED MESSAGE-----

From: "Michael Helm" <helm(_at_)fionn(_dot_)es(_dot_)net>
Could keys and keyservers be configured [optionally] not to
present email-like id's?

Not without almost completely impairing their use.  Yes, it
would be easy to turn off name-based lookups, and/or discard or
alter UserId packets.  But...

If you remove or irreversibly alter the UserID material, then:
(1) associated signatures will fail to verify; and, (2) e-mail system
plug-ins will be unable to do matching.  If you alter them in a way
that is automatically reversible, then any harvester could undo the
alteration just as easily.  You would also have to teach all the
existing tools to undo the alteration(s).

Note that many people use altered addresses in their posts, with the
expectation that they'll be fixed *manually*.  A few people (myself
included) do that for keys they upload.  If the alteration doesn't
affect "words" in the name, then name-based lookups will work against
all?) current keyservers.  Plug-ins may require a more exact
match... since I don't use any, I wouldn't know for sure.  Again,
a smart harvester might use some heuristic de-mangling that would
generate a valid address, but that's a risk I'm willing to live with.
Any "mangling standard" might make it more worth trying.

-----BEGIN PGP SIGNATURE-----
Version: PGP Personal Privacy 6.5.3

iQEVAwUBO4Enm2NDnIII+QUHAQH+DQf/YXZWWbWCMl3Fpa/m9ersiRpRITcUCw70
P5HkHQHVo/mniynfDyxPuu44LMIYKbMkZyeYs2gfZNBZAhiKIB7pYYSK1fx87Q1o
DjSQkOZ+xCITiqb2a/BhJ3900+gVVul7iYKLTaDp3rnyUlsB2oz1A/qOPm2FOfdv
g2+5SJ+Zkwy5PkJtuXWqgQbMqKqm/AExV6mvi2LyPWeN2gJXarA3D+KD+4n4NmDF
gwbbOxrpcjJgTGE6Hd/57okN0gj6Hv8op3SnmFbU8OyN+FRipx93QG/L5aqrV8Zr
iAFd4RnXzn/XXzC9TZfkMJs0O6k7dTRR9ba7C4Kwhjhe2obtFGEbBA==
=WdpU
-----END PGP SIGNATURE-----



<Prev in Thread] Current Thread [Next in Thread>