ietf-openpgp
[Top] [All Lists]

Re: [openpgp] Fingerprints

2015-04-15 17:11:01
On Wed, Apr 15, 2015 at 4:57 PM, Christoph Anton Mitterer
<calestyo(_at_)scientia(_dot_)net> wrote:
On Wed, 2015-04-15 at 16:46 -0400, Phillip Hallam-Baker wrote:
The ni scheme I linked to does essentially that. What we are
discussing here is essentially the same thing only with a slightly
different syntax. It is not necessary to separate the algorithm ID
from the fingerprint.
So in that ni scheme, is the algorithm id then hashed along with the
data?

ni is a URI scheme designed to be used under the covers. It is not
really what I would want for a fingerprint.


Well... it's always difficult to predict the future... probably you're
right, but why making it not generic enough to be one the safe side if
we can.

Because introducing syntactic crud makes the identifier much less
convenient and the whole point of a fingerprint is convenience.

As I demonstrated, the proposed scheme has more than enough generality
for our purposes which are thoroughly understood.



As I've said, we've had that already plenty of times, that people
expected something to be never exhausted and then things came completely
different.
So one should perhaps learn from the past =)

That has happened when people who did not bother to try to understand
the issue refused to listen to the informed opinions of those who did.
While I am prepared to engage in a discussion over whether the basis
of my estimates is reasonable or not, 'other people got it wrong,
therefore you will' is not an argument.

Unlike the people you are citing, I have actually played a significant
role in the deployment of two global scale infrastructures. While I
can't claim to be infallible, I can claim to know something of what I
am doing.


If the need ever arises, we can always cut a completely new set of
fingerprint identifiers by just slapping a URI prefix on the front. Or
use ni.

All we are talking about here is the human readable form of the
identifier. PGP is going to be using the binary data, JSON and XML
apps using the same fingerprint format should use URIs.

_______________________________________________
openpgp mailing list
openpgp(_at_)ietf(_dot_)org
https://www.ietf.org/mailman/listinfo/openpgp

<Prev in Thread] Current Thread [Next in Thread>