[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: PGP to PC mail integration



From:	IN%"[email protected]"  1-MAR-1996 18:50:23.84

>I wrote:
>>	You'd put something into the mail message itself that would tell it
>>"don't encrypt this" and/or "don't sign this". Hmm... you'd need to put in
>>messages to be signed and/or encrypted your passphrase, or have it gotten
>>some other way... which doesn't look very safe.

>Not very user-friendly either.

	That depends on one's standards. I prefer text-based interfaces, and
they are needed for many setups.

>Usually the proxy would be on the same machine as the mail program (i.e. "your
>machine"). That would mean the "attack proxy" would have to be installed on
>the user's PC, and if someone has that kind of access to your machine, their
>secret keyring is vulnerable anyway.

	Good point. This also argues against the passphrase into the mail
being that much of a problem... with the massive exception of something going
wrong with the mail proxy program so that it lets through the email, with the
passphrase and possibly without any encryption.
	However, as has been pointed out on other aspects of this, one could
have the passphrase entered once (in a special mail message with no valid
To: address, for instance) per session.
	-Allen