GnuPG 2.1.0 "modern" released
GnuPG 2.1.0 "modern" released
Posted Nov 13, 2014 10:06 UTC (Thu) by dlang (guest, #313)In reply to: GnuPG 2.1.0 "modern" released by dd9jn
Parent article: GnuPG 2.1.0 "modern" released
So while it doesn't result in a mathematically 'guaranteed[*]' signature, something signed by an old key that looks reasonable still has a very high probability of being what was initially signed.
As for encryption, how does being able to generate a new document that has the same hash as the old one make it possible to see what was in the old document?
I agree with the earlier poster, it's worth preventing these old keys from being used to sign/encrypt new stuff, but it doesn't make sense to prevent them from being used to access existing data (or validate the signature of the old data)
As I said before, it's just not possible to re-sign every document that was created, and even for encryption, if the encrypted version of the document is in the hands of the bad guy, re-encrypting your copy of it will achieve absolutely nothing in terms of preventing the bad guy from decrypting it.
So no, those documents should not be thrown away and their signatures treated as being worthless.
