[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Bug#17959: pgp-i: new upstream version



Folks, we can't drop any pgp 2.6.x version in favour of pgp 5.x.

For the german speaking people: Please read 
<URL:http://www.fen.baynet.de/datenschutz/ld_50.htm>, linked from
<URL:http://www.in-ca.individual.net/software.html>

The release of PGP 5.5 Business contains Company Message Recovery
(CMR).  Even release 5.0 supports CMR.  What is CMR you might ask?
It's similar to key recovery.  You're sending an encrypted message
and without your knowledge it's encrypted with a third key so your
boss (or the government) may read it, too.  Nifty feature, right?

This normally won't work the other way round as a remote user won't
encrypt his message with the company's key, too.  To enable this
additional fields were added (ARR - Additional Recipient Record)
that tell the other pgp program to encrypt the message with an
additional key so the company is still able to decrypt it.

The commandline version of pgp 5.x doesn't provide queries about
the additional encryption.

As a side note this has made several people quite angry who have
scanned and proof-read the pgp books to get an international
pgp release.

There are attempts to release a new version of pgp based on 2.6.x.
Lutz Donnerhake is working on such a thing called pgp 2.6in (cf 2nd
link from above).

This CMR makes pgp quite useless.  Please think of it.

Regards,

	Joey

-- 
   / Martin Schulze  *  joey@infodrom.north.de  *  26129 Oldenburg /
  / linux: Unbekannter Terminaltyp                                /
 / Ich weiß nicht, auf was für einem Terminaltyp Sie arbeiten -  /
/ alles, was ich habe, ist 'linux'.              -- Solaris 2.5 /

Attachment: pgpje3tuYMTN1.pgp
Description: PGP signature


Reply to: