Re: header protection drafts too early to implement (Re: Protect email experience not Subject:s (hypothesis, draft))

2021-03-19 Thread Bernhard Reiter
Am Freitag 12 März 2021 18:02:41 schrieb Bernhard Reiter: > To keep you in the loop, my main take-away so far: > It is not ready to be implemented yet, because If it is implemented, to me it makes sense to a) only implement one method, and this seems to be to wrap one full message in MIME, be

header protection drafts too early to implement (Re: Protect email experience not Subject:s (hypothesis, draft))

2021-03-12 Thread Bernhard Reiter
Took a few hours to read through the current version of Am Freitag 29 Januar 2021 17:52:25 schrieb Bernhard Reiter: > [3] https://datatracker.ietf.org/doc/draft-ietf-lamps-header-protection/ draft-ietf-lamps-header-protection-03 Last updated 2021-02-22 which also aims at OpenPGP/MIME mails. To

protected to: and cc: email infos (Re: Protect email experience not Subject:s (hypothesis, draft))

2021-03-12 Thread Bernhard Reiter
Am Montag 01 Februar 2021 12:32:03 schrieb Andre Heinecke via Gnupg-users: > This discussion is very relevant for me because GpgOL is starting to > include protected-headers mime parts with the next version to transfer To > and CC information. Did you write more about the use case somewhere? My t

Re: Protect email experience not Subject:s (hypothesis, draft)

2021-02-09 Thread Bernhard Reiter
Am Freitag, 29. Januar 2021, 17:52:25 CET schrieb Bernhard Reiter: > From an implementers point of view, protected headers seem to make > it more complicated and break some ways to implement good access > to emails. As Thunderbird as enabled "encrypted" subjects by default with 78 and additionally

Re: Protect email experience not Subject:s (hypothesis, draft)

2021-02-01 Thread Andre Heinecke via Gnupg-users
Hi, On Friday 29 January 2021 17:52:25 CET Bernhard Reiter wrote: > for many months now, my feeling is growing that > > encrypted subject headers in emails > shift the security balance in the wrong direction. I share that feeling. My goal that encrypted mails do not feel much different from

Protect email experience not Subject:s (hypothesis, draft)

2021-01-29 Thread Bernhard Reiter
Hello, for many months now, my feeling is growing that encrypted subject headers in emails shift the security balance in the wrong direction. So I want to summarize and explore this hypothesis. Here are some draft thoughts and notes. Feedback welcome (either to me directly or on the list). N