Ian Goldberg <[email protected]> writes:

> On Fri, Sep 28, 2012 at 02:19:22AM +0100, Ximin Luo wrote:
>> Hi, are there any plans to integrate OTR keys with PGP? (c.f. how
>> monkeysphere integrates SSH keys with PGP).
>> 
>> It's good that crypto products don't also try to provide a PKI and
>> reimplement the wheel, but then they should actually *use* existing
>> ones to fill this gap!
>
> This comes up on the list now and again.  ;-)
>
> One big problem is that there's no way to bind the PGP key for
> "[email protected]" to the AIM ID "angrybob".  Many people already do sign

Sure, but that's not the hard part.   When talking to [email protected],
I often know that I'm trying to talk to [email protected].   having the
FP signed by another key, and clicking yes to 'do you want to allow
[email protected] to sign for [email protected]' uould be great.

> their OTR keys with their PGP keys, so if you (the person, not your
> software) knows that [email protected] is the same person as angrybob, you
> can tell your OTR client that you've verified the keys.  But there's not
> a good way to do this automatically.

People could also put a jid in a uid field in a key.

Attachment: pgpvxEwYPfyti.pgp
Description: PGP signature

_______________________________________________
OTR-users mailing list
[email protected]
http://lists.cypherpunks.ca/mailman/listinfo/otr-users

Reply via email to