|
|
|
|
|
by woodruffw
1342 days ago
|
|
Is there a specific argument you found unconvincing? I thought this was a very well-written summary of (1) why age doesn't provide authenticated encryption by default, (2) how you can do authenticated encryption with age, and (3) why age won't make "simple" authenticated encryption simpler. Edit: I forgot to point out: GPG does sign-then-encrypt, which has a potential failure mode that the post notes (i.e., that your recipient retains your signature, and can encrypt-and-forward it to any additional recipient they please.) |
|
So just like signatures made on paper? You can take a signed paper document and put it in an envelope and send it anywhere you want. What is wrong with that? It is what someone living in this world would normally expect. We need more things that work as expected, not less...