Re: (clug-http) PGP/GPG

Jarrod Major <[email protected]> Thu, 25 Sep 2003 09:33:38 -0600
Newsgroups gmane.org.user-groups.linux.calgary.http
Organization Calgary Linux Users Group
Message-ID <[email protected]>
=2D----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hey Szemir,

Thanks for the in-depth review it was insightful. I guess my biggest concer=
n=20
with building this from the ground up is how much time it will take. Long=20
projects seem to lose interest with CLUG. And personally I would like to se=
e=20
as rapid a change-over as possible. If we can lock down either kind of Nuke=
=20
site then maybe we should stick with that.

I believe that there will be pros and cons for whatever we come up with. I=
=20
like this sort of conversation as it gives us much needed information to ma=
ke=20
an Executive decision.

Thanks again Szemir. I'll try and take a look at those stats myself.

Jarrod

On Wednesday 24 September 2003 8:08 pm, you wrote:
> Hi Jarrod.
> I hope this will be ok gpg-wise :-)
> I can NOT verify your key, no server would do it for me.
> PhpNuke is more popular, the sec faults are very popular with .... you kn=
ow
> who. PostNuke is a tad more secure, BUT has less features. Both will
> support a plugin system, with which we could develope/customize modules as
> we want. Back to the developement issue. Well, no one is perfect, hoever,=
 a
> new developement from scatch, with security in front of the mark one
> eyeball, chances are, there will be very few exploitable sec faults, add =
to
> that, the site will be unique, very few people would have a knolidge of t=
he
> inner workings of the site. Even if we put the source online for download,
> there would be almozt zero chance of an exploit being developen explicitly
> to crack one website. Now that sayed, it might also be a very good idea, =
to
> use a ready made nuke or postnuke and harden it like crazy, plus add the
> wanted bells and stuff, then use it as sutch, this might result in a
> partial rewrite of nuke/postNuke though.
> On a ps note, during the last h4X0r contest, i think a significant portion
> of the defaced sites were nukes. but go check yourself. Now all that may
> not be a security flaw from nuke side, it could be weak passwords, default
> passwords, or other non related weakneses. I am not against nuke, and i
> think it can be made very secure.
>
> Cheers
> Szemir
>
> On Wednesday 24 September 2003 16:55, you wrote:
> > Of course it was GPG I was leaning towards. However, I didn't want to
> > rule out the possibility that someone might have a PGP key as well.
> >
> > Open Source is always my preferred way to go.
> >
> > Jarrod
> >
> > On Wednesday 24 September 2003 4:03 pm, you wrote:
> > > I never touch that.
> > > I don't have any key !
> > > I'm using kmail, which AFAIK support GPG very well.
> > >
> > > always looking for open solutions.
> > >
> > >
> > > Mathieu
> > >
> > > On Wednesday 24 September 2003 11:55 am, you wrote:
> > > > -----BEGIN PGP SIGNED MESSAGE-----
> > > > Hash: SHA1
> > > >
> > > > We need to discuss this as we are going to possible deal in sensiti=
ve
> > > > information.
> > > >
> > > > Can everyone on this list support using PGP/GPG public key
> > > > encryption? Does everyone have a key? Do we need to educate anyone?=
 I
> > > > wouldn't mind getting this nailed down as I am not wholly convinced=
 I
> > > > made mine properly (lots of folks seem to have an issue getting my
> > > > key verified).
> > > >
> > > > What alternatives are available to us? I suppose good old telephone
> > > > could be used if we need to spread usernames and passwords around. I
> > > > don't think it's that serious while things are under development. B=
ut
> > > > then again we are dealing with database security too unless we chan=
ge
> > > > all that once the site is ready to go live.
> > > >
> > > > Some thoughts.
> > > >
> > > > - --
> > > > Jarrod Major
> > > > GPG Fingerprint: FA4A 1EA3 A0EE A842 07BB  804C 0090 14F6 BE6E DE3D
> > > > CLUG President
> > > > Registered Linux User: #224211
> > > > -----BEGIN PGP SIGNATURE-----
> > > > Version: GnuPG v1.2.2-rc1-SuSE (GNU/Linux)
> > > >
> > > > iQCVAwUBP3HaewCQFPa+bt49AQLSmgP/baEKHHW3nyNIuQ+uuAg9r7F6383mqRZ2
> > > > UEGEko+Kv5UmaieBeIjpp5aUAv6DiZgVI743THu5r7vihTTXWM5OJ65N+f37Nj8Z
> > > > R/PjGjLi08VWvIfufVk/oU+mj/YdKh/Ialmao8lCZBQI4mpn/l0gWbFOZoQjsefN
> > > > zSVxtHWv+Y4=3D
> > > > =3DvAzv
> > > > -----END PGP SIGNATURE-----

=2D --=20
Jarrod Major
GPG Fingerprint: FA4A 1EA3 A0EE A842 07BB  804C 0090 14F6 BE6E DE3D
CLUG President
Registered Linux User: #224211
=2D----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.2-rc1-SuSE (GNU/Linux)

iQCVAwUBP3MK2ACQFPa+bt49AQJoCQP/VcPDPP3gJDI86s9B07S4lFLWi4C5ivt4
P52SqqKloMYt5nSTxxj7ZiaKtFbj79dJ0fAMO34hWlIlSzVe6UIyYX7pEgKLuNbF
tvU+lIlitjaXLmVKn/vPPzvMj+WMPkaN4PPdnZHaMYqV5D5zOXVKTC8v1LVAOdJJ
yuuXR7FLbXM=3D
=3DvlQG
=2D----END PGP SIGNATURE-----