ietf-openpgp
[Top] [All Lists]

Re: [openpgp] Mining protection in fingerprint schemes

2016-04-09 09:02:36
Jon Callas <jon(_at_)callas(_dot_)org> writes:

So a way to get both is to make them not the same thing. Have it so that the
thing that you print on your business card is the authentication string, and
the thing that the software is using a lot is the db handle.

That would resolve my pet peeve with the authent strings.  It'd also require
modifying the keyring format to store the keyID as part of the keyring data
rather than requiring that the software processing it calculate the ID for
every single key it finds in a keyring in case it's the required one.  At the
moment PKCS #15 is actually a better PGP keyring format than the native PGP
one because it stores PGP 2/OpenPGP IDs that you can use to index the keys in
a file without having to process the entire keyring and manually calculate the
ID for every key in it just to find a particular key.

Peter.
_______________________________________________
openpgp mailing list
openpgp(_at_)ietf(_dot_)org
https://www.ietf.org/mailman/listinfo/openpgp

<Prev in Thread] Current Thread [Next in Thread>