-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 On 03/05/2013 06:07 PM, Mike Taylor wrote:
+1 > On 03/05/2013 12:04 PM, Peter Saint-Andre wrote: >> I would like to suggest that we change XEP-0027 from Active to >> Deprecated (and then Obsolete). The technology is no longer in >> wide use, and it has so many problems that I don't think we want >> to actively suggest that people implement it. > > > +1 for being proactive at clearing out older (and unwise) info > > >> Peter > > >> -------- Original Message -------- Subject: Re: [cryptography] >> Is it just me or is this fundamentally broken? Date: Mon, 04 Mar >> 2013 18:24:46 -0700 From: Peter Saint-Andre <[email protected]> >> To: Peter Gutmann <[email protected]> CC: >> [email protected] > >> On 3/4/13 4:42 PM, Peter Gutmann wrote: >>> Quoting http://xmpp.org/extensions/xep-0027.html#signing: > >>> Signing enables a sender to verify that they sent a certain >>> block of text. [...] The text that is signed MAY be the empty >>> string. > >>> (There's no metadata or anything there, just a raw signature). > >> No one uses XEP-0027 these days, they all use OTR. The PGP >> integration with XMPP clients was an early experiment in the >> Jabber community before we even called it XMPP. Think 13+ years >> ago. But clients never signed empty strings, although we never >> fixed the spec because no one was using the technology. I'll push >> to make the spec Obsolete. > >> Peter > >> _______________________________________________ cryptography >> mailing list [email protected] >> http://lists.randombit.net/mailman/listinfo/cryptography > > > > -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQIcBAEBCgAGBQJRNwkqAAoJEHZ7UH0X6Ldci8AP/1lXQ1r1HTajFkSvVpov8bGU iEIhP1evYZhE0911KrGhwWAvQEc6S5mV29sVkbQN3gsVv4w2lR/kEOtyn76BgWOt ejpdlRol0PF65UANOhtAKmQS8FvdsK1/agAhwA4BFkEz09kNeG5GBL/8kWthCJGD mzbb4Gj1qtzwncCto6FcXnlbkF+plkBmMBUiFyYGJi+cKLTEZGLqGU5Ah7nEhQEa 733I6/qGx6iUJUzhrxUUn37qe9adrycdkWCVlqyTzt2FQhILXVG7zR1sm64FwTsp da+woTCU3b2JMqJNfxrmF75Cbm6zCxDdUufeJr7SThaKdywdvr2Im2LQyfCgWZ/p h3CrhmsYrcCTGtnMUo+smH2LySP6wuLDfTnc858P/jn/6lmIqxYr3rE0SQzEh4TJ lb7MhmWa9QhoLXzfO6xHDBLksoggu5vZ+DFOggbyvRmOslRDWcrmuqXOJfRuWD2/ /K7VzGGwPWB4wnvTZ3Pr29QrhWdupbDfkeFw2uXuewndwL/089iUQ7NZRZa+NP4t h1Vh4gyrgCGx15sxDKrRtEctByGe1tw4qQMafZcwMi/XzdQ8UPdGni/4azb2/iSQ W9xjLX5KEOFn+ZJHr0IdjHMLATYOer16bqElFXYQLHpIchgJmD77nNPOa5MwjFqA meEE5cEPxPMpJ/CrYmQd =q3/Y -----END PGP SIGNATURE-----
