Re: [dane] Webinterface for DANE-OpenPGPkey look-up available

2016-09-20 Thread Paul Wouters

On Tue, 20 Sep 2016, Martin Rex wrote:


Rene 'Renne' Bartsch, B.Sc. Informatics wrote:


the german mail-provider mail.de has published a web-interface for RFC
7929 look-ups at https://openpgpkey.info/.


That's neat! I tested it out and it found the my pgp key. Perhaps a more
human readable interpretation would have been nice to see as well?


There's definitely no excuse anymore for mail-providers to kick RFC 7929
down the road! ;-)


:)


The concept of the status "Experimental" seems to be unclear to you.


For one, marking it experimental was pretty silly, and based only on
the "we are all going to die over lowercase()" issue. Second, even
expriments need to get their deployments started to see if the RFC
is successfull or not.


And I'm slightly confused to see a comment like this from someone
who seems to come from Europe.  In Europe, publishing such information
is a mandatory end-user-optin (so it requires a non-trivial change
to the backend software), besides screaming out loud "spam-me-harder".


It seems a little ironic that you are invoking privacy laws over
publishing and using _public_ keys eh? :)

And I'm also from European decent but do not see a privacy issue. In
fact, if anything, one can argue that having encryption envelopes
now readily available, sending your personal emails as a postcard
without an encryption envelope would be the privacy law violation.

Paul

___
dane mailing list
dane@ietf.org
https://www.ietf.org/mailman/listinfo/dane


Re: [dane] Webinterface for DANE-OpenPGPkey look-up available

2016-09-20 Thread Martin Rex
Rene 'Renne' Bartsch, B.Sc. Informatics wrote:
> 
> the german mail-provider mail.de has published a web-interface for RFC
> 7929 look-ups at https://openpgpkey.info/. While users have to trust
> mail.de, it allows John-Does to look-up OpenPGPkey-RRs until
> mail-clients support it. The website is now available via IPv4 and IPv6
> protected with DNSSEC/DANE-TLS. Using the DNSSEC/TLSA-Validator from
> CZ-NIC (https://www.dnssec-validator.cz/) John-Does can look-up public
> PGP-keys fairly secure with their browser.
> 
> There's definitely no excuse anymore for mail-providers to kick RFC 7929
> down the road! ;-)


The concept of the status "Experimental" seems to be unclear to you.

And I'm slightly confused to see a comment like this from someone
who seems to come from Europe.  In Europe, publishing such information
is a mandatory end-user-optin (so it requires a non-trivial change
to the backend software), besides screaming out loud "spam-me-harder".

-Martin 

___
dane mailing list
dane@ietf.org
https://www.ietf.org/mailman/listinfo/dane