Re: getross - email privacy /security of system

Bert Driehuis <[email protected]>
Newsgroups gmane.mail.pine.general
Message-ID <[email protected]>
On Mon, 30 Oct 2006, RossARR wrote:

> So how easy is it for any systems operator, administrator, unscrupulous
> characters or such that gain access, to view the email of any user?
> Are we all at the mercy of those that possess the hard drive or can
> access it?

As Kenneth Crudup wrote, it's trivial for a mail administrator to access 
any Pine mailbox.

It is theoretically possible to protect against that (by encrypting all 
mailboxes with the mailbox owners' public keys). However, this has one 
big drawback: if the user loses his private key (or the passphrase to 
it), he will lose all his e-mail, with absolutely no recourse.

There are some software offerings that claim to provide "secure" and 
"encrypted" e-mail whilst allowing the system administrator to "reset" 
lost passwords. Some have been shown to be snake oil, the others... 
well, you can do the math. If the data is recoverable at all, the people 
holding the power to recover have to be trusted in the first place.

It is a matter of taste to decide how secure one wants to make it. In 
most sites I've seen in the days when I audited IT systems, the weakest
links are physical access protection and password quality.
_______________________________________________
Pine-info mailing list
[email protected]
http://mailman1.u.washington.edu/mailman/listinfo/pine-info
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.