ietf-openpgp
[Top] [All Lists]

Re: [openpgp] A way to securely define cleartext signature charset

2018-09-08 13:01:09
Hi,

On Saturday, September 8, 2018 2:19:53 PM CEST Peter Pentchev wrote:
Hmm, is there any way to guard against a false positive identification of
an "old" message that just happens to start with such a line?  I can't
think of any off the top of my head...

I do not think so. Well you could put additional information in the signature 
that will identify it as a cleartext signature following rfc4880bis and only 
then handle the charset header. But I think that would overcomplicate it.

I do not think that a false positivie would not hurt much. PGP Inline charset 
handling is basically guessing so a false positive would just be a false 
guess.

And I think that if someone today signs a message that says

Charset: XYZ

And then continues with some text in another charset it would be weird anyway. 

Don't get me wrong, I *do* see the good things about your proposal.

Thanks! 

Best Regards,
Andre

-- 
Andre Heinecke |  ++49-541-335083-262  | http://www.intevation.de/
Intevation GmbH, Neuer Graben 17, 49074 Osnabrück | AG Osnabrück, HR B 18998
Geschäftsführer: Frank Koormann, Bernhard Reiter, Dr. Jan-Oliver Wagner

Attachment: signature.asc
Description: This is a digitally signed message part.

_______________________________________________
openpgp mailing list
openpgp(_at_)ietf(_dot_)org
https://www.ietf.org/mailman/listinfo/openpgp