DISQUS

DISQUS Hello!  The comments on this profile are unclaimed and thus are unverified.

Do they belong to you? Claim these comments.

Paul's picture

Unregistered

Feeds

aliases

  • Paul

Paul

8 months ago

in FireGPG Firefox Plugin for GnuPG on Michael's Thoughts
Although I will admit to being a bit late in hearing about it, the revelation that Hushmail will roll over and provide decrypted e-mails when presented with a court order (as published in November 2007) makes them or any service that has custody of your private key suspect and vulnerable to LEO access. Since IBE *relies* on a third-party server providing the private key to allow decryption of the e-mail, it is NOT secure. IMO, it's probably *less* secure than Hushmail, which *admits* that they are subject to and will comply with court orders.

Voltage may have the best of intentions, but I have issues with the IBE model they are selling. PGP/GPG, while a bit more difficult to set up, you are the only one that should have access to your private key *and* the passphrase required to decrypt or sign messages. And you're right, you can't make people use PGP/GPG. Like the old saying goes, "You can lead a horse to water, but you can't make it drink."
Returning? Login