Re: PGP keys for [email protected]
Ralf Lang <[email protected]>
| Newsgroups | gmane.comp.horde.devel |
|---|---|
| Message-ID | <[email protected]> |
On 01.07.2014 21:09, Vilius Sumskas/LNK wrote: >>> Quoting Thomas Jarosch <[email protected]>: >>> >>>> Hi, >>>> >>>> given the recent development in world wide data snooping >>>> of government agencies, I guess it would be a good idea >>>> if there's a secure way to report issues to [email protected]. >>>> >>>> Otherwise information about possible exploit vectors might fall >>>> into the "wrong" hands before a fix is publicly released. >>>> >>>> We could define a set of PGP keys on >>>> http://wiki.horde.org/SecurityManagement >>>> that could be used to report issues on the "security" email alias. Or > we >>>> could create a distinct PGP key that's shared among a few trusted > people. >>>> >>>> Opinions? >>> >>> While I don't have any objections to creating a shared PGP key for >>> this purpose, there is really no way to enforce the use of sending >>> an encrypted email. This would require someone to search for, and >>> find, the keys to use. I just don't see the advantage if we can't >>> enforce it. >> >> Well, obviously the sender has to be aware that encryption might be a >> good idea. Chances are that people discovering vulnerabilities are >> aware of that. >> Beside putting the the key(s) on the wiki/website, we would also >> upload it to a PGP keyserver. That's probably the first place where >> security aware people would look for public keys. > > How about replacing email with HTTPS protected web form? Probably Ulaform > could be used for that? This would automatically enforce secure > communication by default. > Forms are good, but if we want people to bother reporting, email should be available. +1 for the PGP key. When it's on the public key servers, people will find it. -- Ralf Lang Linux Consultant / Developer Tel.: +49-170-6381563 Mail: [email protected] B1 Systems GmbH Osterfeldstraße 7 / 85088 Vohburg / http://www.b1-systems.de GF: Ralph Dehner / Unternehmenssitz: Vohburg / AG: Ingolstadt,HRB 3537 -- dev mailing list Frequently Asked Questions: http://wiki.horde.org/FAQ To unsubscribe, mail: [email protected]
signature.asc
(application/pgp-signature, 263 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.22 (GNU/Linux) Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/ iEYEARECAAYFAlOzpKwACgkQCs1dsHJ/X7DZ5wCg91TZDiBXeL8hzg8mvOoYOKVZ 8VsAn1emK8jgEEyo4n8qDVrUmHn0Ijzi =LpO7 -----END PGP SIGNATURE-----