Re: (clug-http) PGP/GPG

Bogi <[email protected]> Wed, 24 Sep 2003 20:08:36 -0600
Newsgroups gmane.org.user-groups.linux.calgary.http
Message-ID <0HLQ00B8MZCF3V@l-daemon>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hi Jarrod.
I hope this will be ok gpg-wise :-)
I can NOT verify your key, no server would do it for me.
PhpNuke is more popular, the sec faults are very popular with .... you know 
who. PostNuke is a tad more secure, BUT has less features. Both will support 
a plugin system, with which we could develope/customize modules as we want.
Back to the developement issue. Well, no one is perfect, hoever, a new 
developement from scatch, with security in front of the mark one eyeball, 
chances are, there will be very few exploitable sec faults, add to that, the 
site will be unique, very few people would have a knolidge of the inner 
workings of the site. Even if we put the source online for download, there 
would be almozt zero chance of an exploit being developen explicitly to crack 
one website. Now that sayed, it might also be a very good idea, to use a 
ready made nuke or postnuke and harden it like crazy, plus add the wanted 
bells and stuff, then use it as sutch, this might result in a partial rewrite 
of nuke/postNuke though.
On a ps note, during the last h4X0r contest, i think a significant portion of 
the defaced sites were nukes. but go check yourself. Now all that may not be 
a security flaw from nuke side, it could be weak passwords, default 
passwords, or other non related weakneses. I am not against nuke, and i think 
it can be made very secure. 

Cheers
Szemir



On Wednesday 24 September 2003 16:55, you wrote:
> Of course it was GPG I was leaning towards. However, I didn't want to rule
> out the possibility that someone might have a PGP key as well.
>
> Open Source is always my preferred way to go.
>
> Jarrod
>
> On Wednesday 24 September 2003 4:03 pm, you wrote:
> > I never touch that.
> > I don't have any key !
> > I'm using kmail, which AFAIK support GPG very well.
> >
> > always looking for open solutions.
> >
> >
> > Mathieu
> >
> > On Wednesday 24 September 2003 11:55 am, you wrote:
> > > -----BEGIN PGP SIGNED MESSAGE-----
> > > Hash: SHA1
> > >
> > > We need to discuss this as we are going to possible deal in sensitive
> > > information.
> > >
> > > Can everyone on this list support using PGP/GPG public key encryption?
> > > Does everyone have a key? Do we need to educate anyone? I wouldn't mind
> > > getting this nailed down as I am not wholly convinced I made mine
> > > properly (lots of folks seem to have an issue getting my key verified).
> > >
> > > What alternatives are available to us? I suppose good old telephone
> > > could be used if we need to spread usernames and passwords around. I
> > > don't think it's that serious while things are under development. But
> > > then again we are dealing with database security too unless we change
> > > all that once the site is ready to go live.
> > >
> > > Some thoughts.
> > >
> > > - --
> > > Jarrod Major
> > > GPG Fingerprint: FA4A 1EA3 A0EE A842 07BB  804C 0090 14F6 BE6E DE3D
> > > CLUG President
> > > Registered Linux User: #224211
> > > -----BEGIN PGP SIGNATURE-----
> > > Version: GnuPG v1.2.2-rc1-SuSE (GNU/Linux)
> > >
> > > iQCVAwUBP3HaewCQFPa+bt49AQLSmgP/baEKHHW3nyNIuQ+uuAg9r7F6383mqRZ2
> > > UEGEko+Kv5UmaieBeIjpp5aUAv6DiZgVI743THu5r7vihTTXWM5OJ65N+f37Nj8Z
> > > R/PjGjLi08VWvIfufVk/oU+mj/YdKh/Ialmao8lCZBQI4mpn/l0gWbFOZoQjsefN
> > > zSVxtHWv+Y4=
> > > =vAzv
> > > -----END PGP SIGNATURE-----
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.7 (GNU/Linux)

iD8DBQE/ck4qsv2SdkgY6dURAnIZAJ9as852vTaLBjE+svyZAw/KcYXZEgCg0IUe
SAFZ2ySPTSIj5ZoBmdGuQLE=
=d2ea
-----END PGP SIGNATURE-----