Reply to post: Re: The issue is less "encryption" and more "identity management"

ISP GMX attempts the nigh impossible: PGP for the masses

Dan 55 Silver badge

Re: The issue is less "encryption" and more "identity management"

The problem is you're supposed to already have the public key, not the message, because you don't know if you can trust the message. You may also want to send a message to them first, but you can't encrypt it because you don't know their public key.

Maybe putting the public key in a header is okay, if they all match from that sender then the mail client can assume it's safe to go ahead. Something like SSH's first connection certificate - it makes things easier and it's probably okay to use.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon