Re: PGP keys for [email protected]

Michael J Rubinsky <[email protected]>
Newsgroups gmane.comp.horde.devel
Message-ID <20140701114414.Horde.v1PCkL29hM4eFX59XtncBA2@h4.theupstairsroom.com>
Quoting Thomas Jarosch <[email protected]>:

> Hi,
>
> given the recent development in world wide data snooping
> of government agencies, I guess it would be a good idea
> if there's a secure way to report issues to [email protected].
>
> Otherwise information about possible exploit vectors might fall
> into the "wrong" hands before a fix is publicly released.
>
> We could define a set of PGP keys on http://wiki.horde.org/SecurityManagement
> that could be used to report issues on the "security" email alias. Or we
> could create a distinct PGP key that's shared among a few trusted people.
>
> Opinions?

While I don't have any objections to creating a shared PGP key for  
this purpose, there is really no way to enforce the use of sending an  
encrypted email. This would require someone to search for, and find,  
the keys to use. I just don't see the advantage if we can't enforce it.

-- 
mike
The Horde Project
http://www.horde.org
https://www.facebook.com/hordeproject
https://www.twitter.com/hordeproject

-- 
dev mailing list
Frequently Asked Questions: http://wiki.horde.org/FAQ
To unsubscribe, mail: [email protected]
smime.p7s (application/pkcs7-signature, 5.7 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.