Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think Matthew Green's point was more that requesting a public key leaks your intent to communicate with someone—the metadata, if you will—to an untrusted third-party.

Of course, e-mail headers, including From and To, must necessarily transit as cleartext, even when e-mail bodies are protected by PGP. The keyserver should perhaps be the least of Matthew's concern.



So... gpg + mixmaster remailers + Tor for http?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: