David Shaw wrote:

> Because they're not joined together it is not a real disambiguation.
> With two UIDs, it is possible for someone to remove one without
> affecting the other.  

OK ... and what would that gain them?

> We've established that people are sometimes
> unwilling to sign "David Shaw" (with no email).

Yes, we've established that ... but not the rationale behind it.

> Having two UIDs, each
> requiring their own signature, is much the same case since the email
> address UID can be removed.

OK, so it makes sense for those who care about the email address to not
trust the key if there is no signed UID containing the email with which
they wish to communicate.

> You don't.  But it's not up to you as the signer - it's up to the key
> holder to say how he wants to be known.

Not really.  It's up to me as the signer to affirm how I know the key
holder.  Or not sign at all if I can't verify all data.

-- 
Bad - You get pulled over for doing 90 in a school zone and you're drunk
off your ass again at three in the afternoon.
Worse - The cop is drunk too, and he's a mean drunk.
FUCK! - A mean drunk that's actually a swarm of semi-sentient
flesh-eating beetles.
OpenPGP key id: 0x51192FF2 @ subkeys.pgp.net

Attachment: signature.asc
Description: OpenPGP digital signature

_______________________________________________
Gnupg-users mailing list
[email protected]
http://lists.gnupg.org/mailman/listinfo/gnupg-users

Reply via email to