in reply to Re^2: OpenID alternatives, what do you suggest
in thread OpenID alternatives, what do you suggest
For email, Thunderbird and mutt support client keys. There's also built-in support for PGP/GPG in mutt to encrypt the email itself. I'm sure there are plugins for Thunderbird to do that if it doesn't already. Many servers can be configured to use TLS-encrypted sessions for MTA to MTA communications when available at the other endpoint.
It's typically considered the MTA's job to deliver the mail first and to concern itself with security second, which is an attitude that needs to change before any of this improves. It does little good to have SSL or TLS sending and receiving if the mail routing in the middle is in plaintext. Encrypting and signing the message at the endpoints with PGP/GPG and sending it through clear channels should offer whole-path protection up to the point where they are easily borken. AFAIK, it still takes quite some time to break a 2048-bit key for GPG.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^4: OpenID alternatives, what do you suggest
by zentara (Cardinal) on Sep 25, 2008 at 16:02 UTC | |
by mr_mischief (Monsignor) on Sep 25, 2008 at 16:09 UTC |