# Why does Discourse block cryptographic signatures by default?

**URL:** <https://meta.discourse.org/t/why-does-discourse-block-cryptographic-signatures-by-default/132912>\
**Category:** Feature\
**Created:** [November 8, 2019, 11:04am UTC](https://meta.discourse.org/t/why-does-discourse-block-cryptographic-signatures-by-default/132912 "2019-11-08T11:04:16Z")\
**Posts on this page:** 1\
**Showing post:** 1

<div class="post-metadata">

**Author:** ![maltfield](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/maltfield/32/160669_2.png) [@maltfield](https://meta.discourse.org/u/maltfield)\
**Post date:** [November 8, 2019, 11:04am UTC](https://meta.discourse.org/t/why-does-discourse-block-cryptographic-signatures-by-default/132912/1 "2019-11-08T11:04:16Z")

</div>

Discourse’s default attachment blacklist includes ‘signature.asc’ files. Why?

- [discourse/config/site\_settings.yml at e92f5e4fbf04a88d37dc5069917090abf6c07dec · discourse/discourse · GitHub](https://github.com/discourse/discourse/blob/e92f5e4fbf04a88d37dc5069917090abf6c07dec/config/site_settings.yml#L638)

It appears that, when attachment blacklists were added to Discourse on 2016-08-03, (commit e92f5e4fbf04a88d37dc5069917090abf6c07dec), the default value for the “attachment\_filename\_blacklist” variable became “smime.p7s|signature.asc” – or to block S/MIME & GPG cryptographic signature attachment files.

- [FEATURE: new email attachment blacklists site settings · discourse/discourse@e92f5e4 · GitHub](https://github.com/discourse/discourse/commit/e92f5e4fbf04a88d37dc5069917090abf6c07dec)

Cryptographic signatures are very small & harmless, yet provide a cryptographic trail for validating the authenticity of a message.

What was the logic in deciding to block them by default?

@zogstrip

---

_[View the full topic](https://meta.discourse.org/t/why-does-discourse-block-cryptographic-signatures-by-default/132912)._
