Evil PGP sigs thread must die. was Re: Stop it with putting your e-mail body in my MUA OT

Brad Knowles brad.knowles at skynet.be
Mon Jul 15 15:35:01 UTC 2002


At 3:45 PM -0400 2002/07/10, Andy Dills wrote:

>  Lest anybody confuse my argument, I think PGP signatures are a good thing.
>  I just don't think people need to sign everything they send. And I'm
>  talking about posts to Nanog here, not private communication. In private
>  communication, it's reasonable to sign most everything sent with official
>  business purpose.

	No.  It is precisely the public e-mail messages which should 
always be signed, since they are the ones likely to reach the largest 
audience, and the ones that are likely to have the biggest negative 
impact if they are successfully spoofed.

	You should sign all private e-mail, too, but the public e-mail 
messages are the ones that need it the most.

-- 
Brad Knowles, <brad.knowles at skynet.be>

"They that can give up essential liberty to obtain a little temporary
safety deserve neither liberty nor safety."
     -Benjamin Franklin, Historical Review of Pennsylvania.



More information about the NANOG mailing list