feature suggestion

Werner Koch wk at gnupg.org
Fri Jan 3 14:06:01 CET 2003


On Thu, 2 Jan 2003 21:36:07 -0500, David Shaw said:

> It seems like a good idea to me as well, but I'm worried about what it
> will mean for various programs that call GnuPG.  The default GnuPG
> config for Mutt, for example, uses the --quiet option.  People may be

I don't think that it is a good idea at all.  The MUA should decide
which address to display and GnuPG provides all required information.

A MUA should even check that the From/Reply-to address matches one of
the user ID in the signature.  Without this it would be easy to trick
someone to reply (probably including quoted decrypted text) to a man
in the middle.


Shalom-Salam,

   Werner





More information about the Gnupg-devel mailing list