How long can you go with an expired key?

coderman coderman at gmail.com
Mon Feb 25 05:06:37 PST 2008


On Sun, Feb 24, 2008 at 5:30 PM, J.A. Terranson <measl at mfn.org> wrote:
> ...
>  I left the expired key on the .sig, and started the clock to see how long
>  it would take for someone to notice.

relying on an active reply / notification to you to determine "notice"
is flawed, "notice" can be passive :)

[besides, much more disconcerting than a long used key expiring, is a
fraudulent key or long deprecated key (rollback) being used, or other
such indicators more worthy of an active "heads up" response or just
extreme scrutiny...]


>  So, CP Distributed Lists are dead.

dead is such a relative term...  :P





More information about the cypherpunks-legacy mailing list