[Enigmail] Expect signature header proposal

Eitan Adler eitanadlerlist at gmail.com
Sat Oct 4 18:19:41 PDT 2008


Robert J. Hansen wrote:
> Eitan Adler wrote:
>> When someone that does use encryption on a regular basis doesn't sign a
>> message most people do not notice.  I propose some kind of extra mail
>> header such as "X-Expect-Sig-Always" be set if you plan on always
>> signing your messages.
> 
> This plan is error-prone, hard to implement correctly, and introduces
> some interesting attacks against the system.
> 
> Sorry, but it's not going to work.
> 
> 
Can you be a bit more verbose?
And can you think of anything else to solve the "not signed when it
should be" problem?


More information about the Enigmail mailing list