Re: PGP keys for [email protected]
Michael J Rubinsky <[email protected]>
| Newsgroups | gmane.comp.horde.devel |
|---|---|
| Message-ID | <20140701114414.Horde.v1PCkL29hM4eFX59XtncBA2@h4.theupstairsroom.com> |
Quoting Thomas Jarosch <[email protected]>: > Hi, > > given the recent development in world wide data snooping > of government agencies, I guess it would be a good idea > if there's a secure way to report issues to [email protected]. > > Otherwise information about possible exploit vectors might fall > into the "wrong" hands before a fix is publicly released. > > We could define a set of PGP keys on http://wiki.horde.org/SecurityManagement > that could be used to report issues on the "security" email alias. Or we > could create a distinct PGP key that's shared among a few trusted people. > > Opinions? While I don't have any objections to creating a shared PGP key for this purpose, there is really no way to enforce the use of sending an encrypted email. This would require someone to search for, and find, the keys to use. I just don't see the advantage if we can't enforce it. -- mike The Horde Project http://www.horde.org https://www.facebook.com/hordeproject https://www.twitter.com/hordeproject -- dev mailing list Frequently Asked Questions: http://wiki.horde.org/FAQ To unsubscribe, mail: [email protected]
smime.p7s
(application/pkcs7-signature, 5.7 KB) - not displayed