pem-dev
[Top] [All Lists]

Re: hiding public key (was: limitations of mime-pem transformation)

1994-12-31 14:00:00

Jeff and Steve,

The PGP community represent a set of users who want to be able to
prevent the disclosure of their public key.

Speaking personally, while I support the idea of non-disclosure of the
public key, if I thought it represented unnecessary complexity I would
vote against it.  Let me observe that the ability to do this "falls out"
of the chosen identifier mechanism, in particular arbitrary key
selectors.

This argument is circular.  The arbitrary key selector was chosen
*because of* the requirement to hide the public key.

The PGP community represent a set of users who want to be able to
prevent the disclosure of their public key.

What I'm asking is this: You accepted the "PGP community's"
requirement to hide the public key.  However, someone from the PGP
community recently said we DER is too complex and we should encode the
public key with the PGP method.  But you did *not* accept *this*
requirement.  Do you see what I'm asking?  What criteria were used to
determine that hiding the public key is a reasonable requirement,
whereas using something simpler than DER is not reasonable?
Just saying "They wanted it" is not an answer.

- Jeff

<Prev in Thread] Current Thread [Next in Thread>