[Enigmail] use of openPGP

Robert J. Hansen rjh at sixdemonbag.org
Wed Sep 26 13:20:24 PDT 2007


loebbe wrote:
> What is the result using OpenPGP ?

Everything.  Nothing.  This question cannot be meaningfully answered.
It's one giant category error, philosophically speaking.

> The email, encrypted and signed can be read by everybody as long as he
> uses OpenPGP

An encrypted email can only be read by those in possession of both a
recipient's private key and the passphrase for that key.

> OpenPGP only shows me, if somebody not only read but also manipulated
> the message.

There is no facility for showing if an email has been read.  It is
unlikely any such provision could ever exist.

There is no facility for showing if a message has been manipulated.  All
that you can demonstrate is if a message is received by you in exactly
the same condition that was certified by another.

You may think these answers are very technical and are phrased in a way
that's hard to understand.  They are.  However, email privacy is a very
technical subject area.  English does not have the words to efficiently
and elegantly talk about these things.  All good, accurate answers will
sound clumsy.

> Therefore if I want to ensure that only the entitled receiver can read
> the message, the message has to be encryted with another
> programm and the receiver has to receive the password in a seperate
> letter or by phone.

No.  Totally incorrect.



More information about the Enigmail mailing list