Re: Procmail feature security hole?
Brought to you by:
ftobin
|
From: Frank T. <ft...@ui...> - 2000-10-03 07:39:41
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Billy Donahue, at 03:18 -0400 on Tue, 3 Oct 2000, wrote: > A line starting with, and matching above some threshold (say 80%) of, > a user's pgpenvelope border should be flagged with (or followed by) a > "WARNING:" of some kind.. This is a harder task to determine than one would think (I think). > Okay, I've done this.. Now I'm safe... :) But now I've got to guard all > of my procmail-verified messages, and make sure I strip the pgpenvelope > borders when I quote things or I risk disclosing my secret markers. > It would be better to come up with a real solution to the problem. The real solution is to do one store/show verification information separately from the message itself. Graphical mailers can do this by popping up another window. If $DISPLAY is set, when verification happens, I could pop up an X message somehow (possibly via xmessage). > The procmail pgpenvelope filter is convenient, but is it worth the risk > of false positives on signatures? Each user has to make that determination on his/her own. - -- Frank Tobin http://www.uiuc.edu/~ftobin/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.3 (FreeBSD) Comment: pgpenvelope 2.9.0 - http://pgpenvelope.sourceforge.net/ iEYEARECAAYFAjnZjTwACgkQVv/RCiYMT6OYZgCaAqqVwMkSsyKx2HCrDg6sfj+y wL0AninJX7aVqdJ0RcdeWvIFPy06QRK3 =qP9s -----END PGP SIGNATURE----- |