User avatar
7h
email musings hm, the more it thinks about email the more it supports tls based pki, just have the fucking tls keys of the domain holder be used for signing account keys, whichbin turn sign emails and also encrypt them
1
0
0
0
User avatar
5225225 @5225225@furry.engineer
7h
@16af93 the recipient mail server can still read the emails if they wanted to (by giving their own keys instead of ones held only by the account holder), no?

though i suppose that does prevent the
sender mail server from seeing the contents, even if both servers are hostile, assuming the key fetching is done by the client
1
0
0
0
User avatar
7h
@5225225 the keys would generally be held by the user's client(s) and just signed by the domain holder
1
0
0
0
User avatar
5225225 @5225225@furry.engineer
7h
@16af93 yeah, i mean "what's preventing the domain holder from just. lying. and presenting their own keys that they generated themselves"
1
0
0
0
User avatar
Celeste_transbian flori_ava_star:~cursor_blinkingbadge-petting-encouraged badge-biting-allowed @star@amazonawaws.com
6h
@5225225 @16af93 polyproto solves this somewhat actually
0
0
0
0