Re: (clug-http) PGP/GPG
Bogi <[email protected]> Wed, 24 Sep 2003 20:08:36 -0600
| Newsgroups | gmane.org.user-groups.linux.calgary.http |
|---|---|
| Message-ID | <0HLQ00B8MZCF3V@l-daemon> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hi Jarrod. I hope this will be ok gpg-wise :-) I can NOT verify your key, no server would do it for me. PhpNuke is more popular, the sec faults are very popular with .... you know who. PostNuke is a tad more secure, BUT has less features. Both will support a plugin system, with which we could develope/customize modules as we want. Back to the developement issue. Well, no one is perfect, hoever, a new developement from scatch, with security in front of the mark one eyeball, chances are, there will be very few exploitable sec faults, add to that, the site will be unique, very few people would have a knolidge of the inner workings of the site. Even if we put the source online for download, there would be almozt zero chance of an exploit being developen explicitly to crack one website. Now that sayed, it might also be a very good idea, to use a ready made nuke or postnuke and harden it like crazy, plus add the wanted bells and stuff, then use it as sutch, this might result in a partial rewrite of nuke/postNuke though. On a ps note, during the last h4X0r contest, i think a significant portion of the defaced sites were nukes. but go check yourself. Now all that may not be a security flaw from nuke side, it could be weak passwords, default passwords, or other non related weakneses. I am not against nuke, and i think it can be made very secure. Cheers Szemir On Wednesday 24 September 2003 16:55, you wrote: > Of course it was GPG I was leaning towards. However, I didn't want to rule > out the possibility that someone might have a PGP key as well. > > Open Source is always my preferred way to go. > > Jarrod > > On Wednesday 24 September 2003 4:03 pm, you wrote: > > I never touch that. > > I don't have any key ! > > I'm using kmail, which AFAIK support GPG very well. > > > > always looking for open solutions. > > > > > > Mathieu > > > > On Wednesday 24 September 2003 11:55 am, you wrote: > > > -----BEGIN PGP SIGNED MESSAGE----- > > > Hash: SHA1 > > > > > > We need to discuss this as we are going to possible deal in sensitive > > > information. > > > > > > Can everyone on this list support using PGP/GPG public key encryption? > > > Does everyone have a key? Do we need to educate anyone? I wouldn't mind > > > getting this nailed down as I am not wholly convinced I made mine > > > properly (lots of folks seem to have an issue getting my key verified). > > > > > > What alternatives are available to us? I suppose good old telephone > > > could be used if we need to spread usernames and passwords around. I > > > don't think it's that serious while things are under development. But > > > then again we are dealing with database security too unless we change > > > all that once the site is ready to go live. > > > > > > Some thoughts. > > > > > > - -- > > > Jarrod Major > > > GPG Fingerprint: FA4A 1EA3 A0EE A842 07BB 804C 0090 14F6 BE6E DE3D > > > CLUG President > > > Registered Linux User: #224211 > > > -----BEGIN PGP SIGNATURE----- > > > Version: GnuPG v1.2.2-rc1-SuSE (GNU/Linux) > > > > > > iQCVAwUBP3HaewCQFPa+bt49AQLSmgP/baEKHHW3nyNIuQ+uuAg9r7F6383mqRZ2 > > > UEGEko+Kv5UmaieBeIjpp5aUAv6DiZgVI743THu5r7vihTTXWM5OJ65N+f37Nj8Z > > > R/PjGjLi08VWvIfufVk/oU+mj/YdKh/Ialmao8lCZBQI4mpn/l0gWbFOZoQjsefN > > > zSVxtHWv+Y4= > > > =vAzv > > > -----END PGP SIGNATURE----- -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.7 (GNU/Linux) iD8DBQE/ck4qsv2SdkgY6dURAnIZAJ9as852vTaLBjE+svyZAw/KcYXZEgCg0IUe SAFZ2ySPTSIj5ZoBmdGuQLE= =d2ea -----END PGP SIGNATURE-----