Re: Hangs getting key
Brought to you by:
ftobin
|
From: Billy D. <bi...@da...> - 2000-07-23 00:38:51
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Sat, 22 Jul 2000, Frank Tobin wrote: > Billy Donahue, at 19:53 -0400 on Sat, 22 Jul 2000, wrote: > > I've definitely recently started considering having the problem solved in > two ways; first, having the procmail filter strip the key from the message > after trying to process it (you could still access it by the recommended > signed-backup) folder. > > Personally, I feel the people putting keys into BugTraq messages are being > quite silly and not showing a lot of gray matter. I agree, but I'm not talking about posting of public keys to bugtraq. I think it makes a LOT of sense to sign messages posted to buqtraq, to make it harder to forge security advisories. These signed messages trigger pgpenvelope_decrypt. > As a temporary workaround, there is a cofirm-decryption described in > ~/.pgpenvelope/prefs.default you may be interested in. I knew about that option, but I'm a keystroke monger, so I don't want to use it unless I really have to. > This is an interesting idea I've played around with; initially I thought > of pgpenvelope doing that, and then exiting with error; unfortunately, > Pine's behaviour is undefined when the filter exits with error. Just now > I thought of having pgpenvelope exit with success instead, and this would > solve the situation, so that's what I think I'll do. Yeah, that's certainly a reasonable way out of a sigint. > BTW, since I don't use pgp4pine, what points caused you to use > pgpenvelope, and are there any points of pgp4pine that you miss? The biggest thing that brought me over to pgp4pine was when I imported a friend's key and all of a sudden pgp4pine stopped working. :) I cleared the cache file, to no avail.. something was just wrong.. Rather than deal with it headfirst, I ran into the arms of pgpenvelope, and I'm pretty happy with it so far. Hmm.. pgp4pine took fewer keystrokes to send a signed message. I'd type (a) and that would 'sign' or 'sign and encrypt' depending on whether I had keys for all of the recipients. I got into the habit of typing 'a', $passphrase, '\n' (forgive my pseudoperl). With pgpenvelope, I have to manually select encrypting, and signing is always checked by default. Maybe a recipient match should be run. pgp4pine has a stored cache of the uids in your keyring, so it can do this instantly. Pgpenvelope is more flexible with key selection, which is cool. Another point of comparison is startup speed. pgpenvelope is perl, and takes a while to get going. This probably can't be helped much. pgp4pine is a 'c' program, and it starts up _much_ faster... This is a big deal when I'm quickly scanning my messages in Pine.. However, I remember that pgp4pine wasn't too sharp on keys with multiple uids. I think it would only get the first uid on the key. - -- "The Funk, the whole Funk, and nothing but the Funk." Billy Donahue <mailto:bi...@da...> -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.1 (GNU/Linux) Comment: pgpenvelope 2.8.10 - http://pgpenvelope.sourceforge.net/ iD8DBQE5ej9K+2VvpwIZdF0RAjY9AJ9xSnkPpoGxMcq3sP9q7hBvzvqhmACgilGk GJpKz/M7+jjpAcrXMzvNrHA= =9Tgh -----END PGP SIGNATURE----- |