[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Bug#466669: Squirrelmail plugin for GPG



Hello Thomas Goirand,

Am 2011-04-04 22:31:26, hacktest Du folgendes herunter:
> Excuse me to say it this way, but the excuse that it's dangerous to keep
> a key on a server is a silly reason for not sending the package in main.
> There's many more reasons you would like to use this package, for
> example to CHECK for a signature. That doesn't require uploading or
> generating a key on the server, yet there's no other way but to use this
> package, if you use Squirrelmail.
> 
> Now, I agree that a warning could be added to the package description.
> But it's the responsibility of an administrator to use (or not) keys on
> the server side. As for me, I would do so only for small low-security
> things, like signing my outgoing mail. Using a key for signing my
> outgoing mail is better than not signing at all, and myself and 5 other
> people are the only one using the server. How in this kind of case, is
> this a security threat? Why would it be considered less safe, than,
> let's say, browsing the web using Adobe flash player on my laptop?

I fully aggree with you.

> The fact that upstream is dead is a much bigger concern though. Did you
> try to ping him once more?

I have tried too, to contact him several times, because it does not more
work with squirrelmail 1.5.x and it seems, upstream is realy  death  and
require someone which can take over.

Note:   I use Squirrelmail in my Intranet, where
        I have absolutely no security concerns.

> Thomas

Thanks, Greetings and nice Day/Evening
    Michelle Konzack

-- 
##################### Debian GNU/Linux Consultant ######################
   Development of Intranet and Embedded Systems with Debian GNU/Linux

itsystems@tdnet France EURL       itsystems@tdnet UG (limited liability)
Owner Michelle Konzack            Owner Michelle Konzack

Apt. 917 (homeoffice)
50, rue de Soultz                 Kinzigstraße 17
67100 Strasbourg/France           77694 Kehl/Germany
Tel: +33-6-61925193 mobil         Tel: +49-177-9351947 mobil
Tel: +33-9-52705884 fix

<http://www.itsystems.tamay-dogan.net/>  <http://www.flexray4linux.org/>
<http://www.debian.tamay-dogan.net/>         <http://www.can4linux.org/>

Jabber linux4michelle@jabber.ccc.de
ICQ    #328449886

Linux-User #280138 with the Linux Counter, http://counter.li.org/

Attachment: signature.pgp
Description: Digital signature


Reply to: