ietf-openpgp
[Top] [All Lists]

Re: OpenPGP vs. OpenPGP/MIME

2002-02-14 02:12:08

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Wednesday 13 February 2002 20:09, Jon Callas wrote:
At 10:50 AM +0100 2/13/02, Thomas Roessler wrote:
does not work with many mailing lists (that are configured to
remove attachments),

Such mailing lists are broken.
<snip>
I must respectfully disagree with this assessment. People who
maintain computer systems used by a number of people have a
responsibility to protect that shared resource. Stopping attachments
on mailing lists is not any more "broken" than putting up a firewall
is.
<snip>

A mailing list software isn't broken because it filters out attachments, 
but because it can't distinguish pgp/mime signed plain text messages 
from attachments. Not everything consisting of a mulitpart contains an 
attachment.
In fact, it would be totally legal for me to always send multipart 
messages, where, for instance, the first nested body part contains the 
text of the mail and the secons one my signature.

I can't speak for Thomas, but that's probably what he meant: That 
mailing list software needs to be able to distinguish between 
attachments and signed messages.

(Though I can understand why Thomas could find ml's which filter all 
"attachments" broken: You can't even forward a message to them (needs a 
multipart/mixed with nested message/rfc822 - eek)).

Marc

- -- 
Marc Mutz <mutz(_at_)kde(_dot_)org>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (GNU/Linux)
Comment: For info see http://www.gnupg.org

iD8DBQE8auQx3oWD+L2/6DgRAlJPAKCrS7BzalfRAck+5T2X+RipCbz7vgCePn2e
Vq6YiYsBw36Qd/aF0cXA54U=
=cA/N
-----END PGP SIGNATURE-----