Mutt/GnuPG doc initial release

Mon Sep 24 19:57:02 2001

Alexander Skwar wrote:
I don't think so.
> So, it doesn't add anything which means that it's unneeded and thus poor
> netiquette.
And I think you are wrong or haven't done proper threat analysis. Case 1: someone impresonating Werner posts a message about a bug in GnuPG and a patch to fix it. This patch actually plants a backdoor. In your approach, you have no way to tell nor it makes any difference to you. Case 2 (real life example): a friend of mine is an active usenetter, she also posts a lot to mailing lists. One day a sexually suggestive (at the verge of explicit) forged messaged attributed to her started to appear. PGP signing was the simplest way to make a good distinction of which messages come from her and which are forgeries. In saying about 'strangers' you forgot one thing: while on everyday use of PGP there is little need to use it to establish RL identity, it is a very good and a convenietnt way of establishing origin. I don't care much if Werner's name is actually Werner, but I do care if new GPG releases come from its author. A good example is remailer-operator list. Anon remailer operators need not to know each other's identities (I'm one of the few who reveal their names) but need to know if given remailer configuration changes come from the remailer's operator (because of MITM).