Fire 1.5.2rc1 Critical GPG Bug

Michael Diehr <[email protected]> Wed, 27 Apr 2005 09:54:16 -0700
Newsgroups gmane.network.fire.devel
Message-ID <[email protected]>
I just tried Fire 1.5.2rc1 on Mac OS X 10.3.9 with a Jabber account, 
and unfortunately it still contains the awful GPG bug:  Fire claims to 
be using Encryption + Signing (Red Lock Icon) but is in fact sending 
messages in Plain Text.

In fact, none of the GPG combinations work (Signing, Sign + Encryption, 
Encryption only) -- all send messages as plaintext.

In my opinion this is a CRITICAL bug, as it misleads users in to a 
false sense of security -- not only does the encryption fail, but the 
user interface shows that encryption is being used!

FYI this bug seems to have been introduced in 1.5.   All my Jabber and 
GPG-using friends have reproduced it.

Thanks!
-mike

To see this bug in action, get a copy of tcpflow from 
http://www.entropy.ch/software/macosx/#tcpflow  and enter the command:
   sudo /usr/local/bin/tcpflow -c port 5222
or
  sudo /usr/local/bin/tcpflow -c port 5223

depending on if you are using SSL or not



-------------------------------------------------------
SF.Net email is sponsored by: Tell us your software development plans!
Take this survey and enter to win a one-year sub to SourceForge.net
Plus IDC's 2005 look-ahead and a copy of this survey
Click here to start!  http://www.idcswdc.com/cgi-bin/survey?id=105hix