Re: getross - email privacy /security of system

Ross <[email protected]>
Newsgroups gmane.mail.pine.general
Message-ID <Pine.WNT.4.61.0611070036160.-1575497@computer101>
On Sun, 5 Nov 2006, Ryan Barrett wrote:
> On Mon, 6 Nov 2006, RossARR wrote:
>> It so happens that Outlook Express & Mozilla, client software, & most 
>> email client software possess encryption of some type now for several
>> years.

> wow, is that true? i'd meant that they'd need to include encryption, PGP
> style, in their base installs. outlook and thunderbird already do that?!? 
> or do you just mean there are plugins available?

No, I said of some type of encryption, I am not aware of PGP 
being used in any client software except HushMail.com stuff. 
Check them out for a good read.

But the demand & user need is already there, & client software 
like OutlookExp 5.5 & Mozilla Suite 1.7.12 (Thunderbird I am not 
familiar with) carries the encryption option. Their type 
encryption is integrated, not plugged in as I can determine. It 
installs ready to go with the program. Yet Mozilla Suite accepts 
plug-ins very well & some PGP may exist - I am not aware of that 
either, but will look.

Any Windoozzz stuff bothers me though, because of Windoozzz 
history - security. If the underlying system is buggy - why 
bother?  Dropping to DOS or better Linux seems long term for most 
security minded People. But too many lazy People are sticking to 
Windoozz for now. So maybe a reliable Pine with PGP is the only 
present way to go. To provide it to other users. Beats nothing.

>> Webmail like Google, Yahoo, Hotmail, not being client software setup on 
>> the
>> users PC, will never be acceptable due to the in-house problem of
>> compromise. To encrypt there is worthless as was previously stated here 
>> in a

> i don't believe that's true. webmail providers could easily encrypt and
> decrypt in javascript, on the local machine. they themselves would only 
> see ciphertext. a number of sites already do this for credit cards.
> even better, since it's javascript, open source security people could 
> audit it to make sure the webmail providers are doing it right.

They would control the program you suggest though?  The source 
code?  Any provider can also be a taker. If they are granted 
authority to access your system to perform the task, they can do 
it their way. That is a security breach to me. Any audit worth 
anything would require verification that would expose the 
message. So why bother?  Anyway, to use webmail, you access the 
software online, not using client software like Mozilla. That is 
exposure.

Trust yourself & who you communicate with only. There must be a 
firewall. We trust PGP only because most of us can not write a 
crypto system ourselves. Newer PGP, especially Windooz versions I 
do not trust. Even Zimmerman scorned that originally. MS, 
Windooz, is a defective system. Yet most of us run Windooz just 
to access the inet.
_______________________________________________
Pine-info mailing list
[email protected]
http://mailman1.u.washington.edu/mailman/listinfo/pine-info
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.