Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

There is a key for encryption, signing, authentication and certification in OpenPGP. The flags are C, E, S, A. The use cases are separate.

Perhaps another flag for automatic vs non automatic would help.



Encryption is not just for encrypted emails.


In theory. In practice, published PGP encryption subkeys has only seen adoption in emails.

Besides, is the criticism that people are using published keys for email? It seems people are outraged that they received encrypted data using keys that they themselves advertised. The specific medium for data transfer doesn’t seem to matter here.


There are separate flags for communications (like email) and storage (like files).

https://datatracker.ietf.org/doc/html/rfc4880#section-5.2.3....


Great, but while the encryption vs signing choice is presented by common software (albeit in a way that does not make this consequence clear), it completely does not present the encrypt for communication and encrypt for storage options.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: