Thunderbird should automatically refresh known OpenPGP keys from keyservers/WKD and possibly other sources (e.g. DNS)
Categories
(MailNews Core :: Security: OpenPGP, enhancement)
Tracking
(Not tracked)
People
(Reporter: KaiE, Assigned: KaiE)
References
Details
(Whiteboard: email-crypto-improvement-tracker)
Attachments
(1 file)
Thunderbird should automatically refresh known OpenPGP keys from keyservers/WKD.
I think that enabling refreshing of OpenPGP keys by default, for all users, requires that we implement lookup privacy as a precondition (bug 1873171).
| Assignee | ||
Comment 1•2 years ago
|
||
Depends on D197768
Updated•1 year ago
|
| Assignee | ||
Comment 2•6 months ago
|
||
(In reply to Kai Engert [:KaiE:] from comment #0)
I think that enabling refreshing of OpenPGP keys by default, for all users, requires that we implement lookup privacy as a precondition (bug 1873171).
I've changed my opinion. I no longer believe the strong privacy is a precondition.
Having updated keys is very important, to learn whether a key is revoked or not, or whether it has been extended after it expired.
I think that we should offer an option for users to route through a privacy protecting network, optionally.
Users who are worried about the leaking of their social graph can enable that pref, and configure Tor.
It would still be good to implement some of the ideas from bug 1873171 eventually, so that at some point we could enable that privacy by default.
| Assignee | ||
Updated•6 months ago
|
Description
•