[Enigmail] Expect signature header proposal

Robert J. Hansen rjh at sixdemonbag.org
Sat Oct 4 18:18:24 PDT 2008


Eitan Adler wrote:
> When someone that does use encryption on a regular basis doesn't sign a
> message most people do not notice.  I propose some kind of extra mail
> header such as "X-Expect-Sig-Always" be set if you plan on always
> signing your messages.

This plan is error-prone, hard to implement correctly, and introduces
some interesting attacks against the system.

Sorry, but it's not going to work.




More information about the Enigmail mailing list