Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

There are multiple uses for keys.

I've published a key so that people can verify the signatures on some software releases. I don't expect anyone to try sending me an email encrypted with that key. And I really wouldn't expect such an email to work.



And that is why there is different types of subkeys, which you are told about when generating the keys, and every "getting started" guide I've found. If you don't want to receive encrypted emails, don't share a subkey for encrypting email?


What's the subtype that's for encrypting emails? Last I looked, there's a subtype for encryption, with no specificity for what medium.


Not for email specifically, but there is a flag for encrypted communications and another for signing.

https://datatracker.ietf.org/doc/html/rfc4880#section-5.2.3....

I believe separate keys for encryption and signing is the default in most implementations.


Sure, but there are things for encryption other than email. Publishing an encryption key does not imply that emails sent to me should be encrypted to that key.


Yep, same. I find it funny that I'm apparently un-emailable by anyone on Proton. Good thing no one actually uses email for communication.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: