TOFU

Andrew Gallagher andrewg at andrewg.com
Wed Jun 7 15:17:12 CEST 2017


On 2017/06/07 13:24, Peter Lebbing wrote:
> Not necessarily!
> 
> I don't know if Enigmail checks whether the From: is equal to the key
> UID, but we're talking about look-alike addresses here, not completely
> equal addresses, so even that wouldn't help.

If I send an email to myself from my new work email, but sign it with my
old personal key (which doesn't have my new work email as a UID), it
still shows up as green in Enigmail. Now, that may be because I'm using
an ultimately trusted key - but it's still not what one might naively
expect.

A

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 801 bytes
Desc: OpenPGP digital signature
URL: </pipermail/attachments/20170607/b00d9769/attachment.sig>


More information about the Gnupg-users mailing list