Hi, On Wed, 07 Nov 2018 at 18:20:16 +0000, Ian Jackson wrote: > Personally I think the hash is bizarre. Why make this protocol depend > on an obsolete hash function ? One could just url-encode the email > address. The server could deal with case-folding etc.
Dunno if you'll find the arguments convincing, but FWIW this was brought up to gnupg-devel in May 2016: see https://lists.gnupg.org/pipermail/gnupg-devel/2016-May/031068.html and follow-ups in that thread. Cheers, -- Guilhem.
signature.asc
Description: PGP signature