Elgamal signatures (was Re: splitting keys)

David Picon Alvarez eleuteri@myrealbox.com
Fri Feb 21 22:46:02 2003


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

> I guess it depends on why you are signing.  If the intent is to get
> other people to check the signatures on your messages to verify they
> did indeed come from you, then it does sort of defeat the purpose of
> signing if checking the signature is so unpleasant that nobody does
> it.

OK, I see this, it's just that it doesn't take me nearly as much to generate
or check my own sigs. Maybe I don't have enough perspective about this.


> There are many reasons not to use Elgamal signatures.  Only GnuPG
> supports them, so you can't communicate with any other OpenPGP
> program.  They are also incredibly slow, which means people have to
> sit for 10-20 seconds every time they need to check one of your
> messages.  If they have their mail reader configured to automatically
> verify signatures, then they can be reading happily along, hit one of
> your messages, and they're locked up for a while.

OK, OK. I guess I'll make an RSA key and loose the few signatures I managed
to collect :-)


Is this better then?

- --David.

-----BEGIN PGP SIGNATURE-----
Comment: This message is digitally signed and can be verified for authenticity.

iQIVAwUBPladiqYOp7uFKb/EAQKuvw/+O8hgJpuykqfEcPGCjWzzxmM8ZgCydRYC
+yXwJcmCWdHt4GkWCoxuMhK7PbfF07FQTj+hddNw9DCPyII03n8EjKZUHiIYkRZ6
IlfaNzYk/2/fu+G7kC+O6GxyR7LmTf4StcnWn7V8GasrYYb/QXT7NDNDepT0DJrC
Qob+O7svwqwnRU+MBv6c2GJCFZkx/7oQIxrZEeaPr1BezsqPJQ4I57cnEEjamGLr
OrcnrClLaeQc4SK1EBJUlsGWMdmikX4wFQ1k1r9J2yyc6WGUynscGjALTeFVPxiK
xkoalyjAQj3+dkgAdxOy25hoEO3eXEY0aFYxQ220/4lmuUS/T0G5ep7OXs4KoNR+
JljJ894DElvvRkgEENQQ3qPLdyWTXIv2gkDKxR+vRhl0EWVw3an6QZ2aTxdd2TUS
eFhh84bDive+JT3536n7aXDolpKs5+x1yG6NZgFpnY/aNQfY7n8Xv9gx3pBA2Jdq
w7qzhWZSR94qYJkWfD2YEv1ynyLD5bsQeJGKWibfIXBk4HxOTuEJbpBDZi4MdGsA
7Tia0M/WihyKCZVGvLnzsMma4SU5adc4h609M2yGtUdAsiRFeyZC/evbOzF53aTG
nnN29iLWI6upq+ZgqRIM+c4od8pOAda/B7+Y6Joh0Q7Z7xGL73xxLX8q/5m0/0JW
guM0bI2I4tI=
=FvE9
-----END PGP SIGNATURE-----