[fwd] Re: PGP/MIME implementors: text mode vs. binary mode? (from: hal@finney.org)

Taral taral@taral.net
Thu Feb 15 18:02:02 2001


--z0eOaCaDLjvTGF2l
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Thu, Feb 15, 2001 at 08:57:56AM +0100, Thomas Roessler wrote:
> In this case, you'd have to come up with some other well-defined
> encapsulation which permits you to include meta-information with the
> signed material, thereby protecting it.  This does, in particular,
> mean that sender and recipient would have to apply this
> transformation to the data, and that this transformation would have
> to be well-defined down to a single bit.  (You couldn't even use
> PGP's packet format, since you can represent the same data in
> different ways there.) Now, why shouldn't MIME be taken for this?
> Just so some people can play around with others'
> content-transfer-encodings in transfer, which is a bad idea in any
> event?

I'm not sure why you're insisting on a deterministic encoding here. You
think MIME has deterministic encodings? The following are two perfectly
valid encodings for the same data in quoted-printable:

Blah blah
Blah=3D20blah

The point is to make the original signed data recoverable, which does
not require absolute determinism in the encoding stage.

--=20
Taral <taral@taral.net>
Please use PGP/GPG to send me mail.
"Never ascribe to malice what can as easily be put down to stupidity."

--z0eOaCaDLjvTGF2l
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.4 (GNU/Linux)
Comment: For info see http://www.gnupg.org

iEYEARECAAYFAjqMC18ACgkQ7rh4CE+nYElD/ACg2ShTxrZuPPkL8XTWGF7dLIdj
BAkAoOWbtwYfz9Rf9LJak4UBL116Kkrm
=4dm1
-----END PGP SIGNATURE-----

--z0eOaCaDLjvTGF2l--