Re: getross - email privacy /security of system
Ross <[email protected]>
| Newsgroups | gmane.mail.pine.general |
|---|---|
| Message-ID | <Pine.WNT.4.61.0611070036160.-1575497@computer101> |
On Sun, 5 Nov 2006, Ryan Barrett wrote: > On Mon, 6 Nov 2006, RossARR wrote: >> It so happens that Outlook Express & Mozilla, client software, & most >> email client software possess encryption of some type now for several >> years. > wow, is that true? i'd meant that they'd need to include encryption, PGP > style, in their base installs. outlook and thunderbird already do that?!? > or do you just mean there are plugins available? No, I said of some type of encryption, I am not aware of PGP being used in any client software except HushMail.com stuff. Check them out for a good read. But the demand & user need is already there, & client software like OutlookExp 5.5 & Mozilla Suite 1.7.12 (Thunderbird I am not familiar with) carries the encryption option. Their type encryption is integrated, not plugged in as I can determine. It installs ready to go with the program. Yet Mozilla Suite accepts plug-ins very well & some PGP may exist - I am not aware of that either, but will look. Any Windoozzz stuff bothers me though, because of Windoozzz history - security. If the underlying system is buggy - why bother? Dropping to DOS or better Linux seems long term for most security minded People. But too many lazy People are sticking to Windoozz for now. So maybe a reliable Pine with PGP is the only present way to go. To provide it to other users. Beats nothing. >> Webmail like Google, Yahoo, Hotmail, not being client software setup on >> the >> users PC, will never be acceptable due to the in-house problem of >> compromise. To encrypt there is worthless as was previously stated here >> in a > i don't believe that's true. webmail providers could easily encrypt and > decrypt in javascript, on the local machine. they themselves would only > see ciphertext. a number of sites already do this for credit cards. > even better, since it's javascript, open source security people could > audit it to make sure the webmail providers are doing it right. They would control the program you suggest though? The source code? Any provider can also be a taker. If they are granted authority to access your system to perform the task, they can do it their way. That is a security breach to me. Any audit worth anything would require verification that would expose the message. So why bother? Anyway, to use webmail, you access the software online, not using client software like Mozilla. That is exposure. Trust yourself & who you communicate with only. There must be a firewall. We trust PGP only because most of us can not write a crypto system ourselves. Newer PGP, especially Windooz versions I do not trust. Even Zimmerman scorned that originally. MS, Windooz, is a defective system. Yet most of us run Windooz just to access the inet. _______________________________________________ Pine-info mailing list [email protected] http://mailman1.u.washington.edu/mailman/listinfo/pine-info