What is the benefit of signing an encrypted email

Daniel Kahn Gillmor dkg at fifthhorseman.net
Wed Jan 12 17:24:35 CET 2011


On 01/12/2011 11:13 AM, Robert J. Hansen wrote:
> Show me the worth in a signed message that has any of (a) an incorrect
> signature, (b) from an invalid key, or (c) from someone you believe is
> utterly untrustworthy.

As a devil's advocate, i'd point out that a message signed with a valid
key known to belong to someone who is utterly untrustworthy could be
used *against* the signer, by saying something like:

 "look -- here is Mr. X claiming that he is going to poison the
reservoir.  Please take this seriously, and note that it could only have
come from Mr. X because it is signed with his key."

This doesn't mean that Mr. X is actually going to poison the reservoir,
but the signature is a good argument that the reservoir guards should
investigate this particular individual -- that the message is not a
forgery from someone trying to tarnish Mr. X's reputation.

Signing a message makes you somewhat more vulnerable -- it is a
non-repudiable statement bound to your identity, which people can use
against you.  It is also a way of standing behind what you are saying,
and accepting responsibility for it.  This kind of tradeoff needs to be
made consciously, and is one of the reasons that you need to take good
care to protect your secret keys.

Regards,

	--dkg

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 900 bytes
Desc: OpenPGP digital signature
URL: </pipermail/attachments/20110112/24c68c08/attachment.pgp>


More information about the Gnupg-users mailing list