<?xml version="1.0" encoding="ISO-8859-1"?>
<?xml-stylesheet href="http://bugs.horde.org/themes/feed-rss.xsl" type="text/xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
 <channel>
  <title>Minimize lacking PGP forward secrecy with webmail</title>
  <pubDate>Sun, 07 Sep 2008 04:01:06 -0400</pubDate>
  <link>http://bugs.horde.org/ticket/5753</link>
  <atom:link rel="self" type="application/rss+xml" title="Minimize lacking PGP forward secrecy with webmail" href="http://bugs.horde.org/ticket/5753/rss" />
  <description>Minimize lacking PGP forward secrecy with webmail</description>

  
  
  <item>
   <title>PGP lacks forward secrecy, i.e. once a secret key with corre</title>
   <description>PGP lacks forward secrecy, i.e. once a secret key with corresponding passphrase is known to an attacker, all prior and all future mails can be decrypted if intercepted. Webmail applications are especially vulnerable to keylogger (or looking over ones shoulders) attacks because they are often used in insecure environments. Horde lets you export the secret key thus one successfull attacks suffices to compromise all prios and all future mails. I therefore suggest to omit this &quot;feature&quot; (exporting of the secret key) in future versions.

I think, it is not really important for users to export their secret key. If they wish to have a copy on their harddisk, they should have a secure place anyway and thus probably have the possibility to generate a key pair on this system and import it into Horde afterwards. If they want to change to a local mailsystem, they should generate a new key anyway if it was possible to export the key without their knowledge beforehand.</description>
   <pubDate>Thu, 27 Sep 2007 12:00:28 -0400</pubDate>
   <link>http://bugs.horde.org/ticket/5753#t37133</link>
  </item>
  <item>
   <title>Seems to me like if people use Horde to generate their key t</title>
   <description>Seems to me like if people use Horde to generate their key they should be able to download it at least at that specific time to back it up - and to get a warning then about losing it, etc. But otherwise this seems reasonable to me. Any other thoughts/objections?</description>
   <pubDate>Fri, 28 Sep 2007 22:54:13 -0400</pubDate>
   <link>http://bugs.horde.org/ticket/5753#t37192</link>
  </item>
  <item>
   <title>Agreed.</title>
   <description>Agreed.</description>
   <pubDate>Sat, 29 Sep 2007 04:26:37 -0400</pubDate>
   <link>http://bugs.horde.org/ticket/5753#t37218</link>
  </item>
  <item>
   <title>&gt; Seems to me like if people use Horde to generate their key</title>
   <description>&gt; Seems to me like if people use Horde to generate their key they 
&gt; should be able to download it at least at that specific time to back 
&gt; it up - and to get a warning then about losing it, etc. But otherwise 
&gt; this seems reasonable to me. Any other thoughts/objections?

the idea with the only download possibility while generating is great. However it might be as well a good idea to give the possibility to view/download a revocation certificate and/or send  one to a keyserver (like you can do it with your public key). otherwise there might be the problem that people want to generate a new key, but can't revoke the old one.</description>
   <pubDate>Sat, 29 Sep 2007 10:16:11 -0400</pubDate>
   <link>http://bugs.horde.org/ticket/5753#t37225</link>
  </item>
  

 </channel>
</rss>
