> However, there is still the status bar to help in the confirmation (and
> designed for that purpose).  

If i write a message to the mutt list, sign it with my key, and forge a from
header that makes it appear to come from you, the status bar will display,
"PGP signature successfully verified." and the only signal to the user that
something is up will be the PGP text, which would say something like:

[-- PGP output follows (current time: Fri 29 Mar 2002 03:26:10 PM EST) --]
gpg: Signature made Fri 29 Mar 2002 03:24:44 PM EST using DSA key ID 8937D7B6
gpg: Good signature from "Mike Schiraldi <[EMAIL PROTECTED]>"
gpg:                 aka "Mike Schiraldi <[EMAIL PROTECTED]>"
[-- End of PGP output --]


If that report were printed at the end of the message, i could just end my
message with a ton of blank lines and few people would bother scrolling to
the end.


-- 
Mike Schiraldi
VeriSign Applied Research

Attachment: msg26403/pgp00000.pgp
Description: PGP signature

Reply via email to