[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: PGP to PC mail integration



On Thu, 29 Feb 1996 15:50 EDT, you wrote:

>	You'd put something into the mail message itself that would tell it
>"don't encrypt this" and/or "don't sign this". Hmm... you'd need to put in
>messages to be signed and/or encrypted your passphrase, or have it gotten some
>other way... which doesn't look very safe.

Not very user-friendly either.

>An attacker could still potentially slip
>something in between the mail program and the proxy program, though - the same
>problem as with the passphrase in the message. 

Usually the proxy would be on the same machine as the mail program (i.e. "your
machine"). That would mean the "attack proxy" would have to be installed on the
user's PC, and if someone has that kind of access to your machine, their secret
keyring is vulnerable anyway.