Re: Policy Update Proposal -- Remove Email Trust Bit

2015-10-13 Thread R Kent James
Great job description, Kathleen, and thanks for working toward keeping this technical capability available. I have some questions about the financial aspects of this, or if there is a better place to discuss this issue please redirect me. Obviously have a "resource" implies that there is

Re: Policy Update Proposal: Remove Code Signing Trust Bit

2015-10-04 Thread R Kent James
ecurity" and let's work together to get it fixed. R. Kent James Chair, Thunderbird Council @rkentjames ___ dev-security-policy mailing list dev-security-policy@lists.mozilla.org https://lists.mozilla.org/listinfo/dev-security-policy

Re: Policy Update Proposal -- Remove Email Trust Bit

2015-09-25 Thread R Kent James
that Mozilla as a whole is going to take up the cause of end-to-end email encryption in Thunderbird. Don't take that as disparaging toward Mozilla, they just have other priorities at the moment. R. Kent James Chair, Thunderbird Council @rkentjames ___ dev

Re: Firefox security too strict (HSTS?)?

2015-09-23 Thread R Kent James
On 9/16/2015 3:01 PM, AnilG wrote: Yes, I agree. From my limited perspective and knowledge I trust you as an authority that that's probably completely correct. But that's not the issue. I've got a concern that security management in Firefox is too hard for enterprise and may additionally have

Re: Firefox security too strict (HSTS?)?

2015-09-23 Thread R Kent James
On 9/23/2015 1:57 PM, Eric Mill wrote: I'd phrase it instead as: what can be done to educate people responsible for deploying/buying enterprise software deployment that a rapid update path for all software/protocols/ciphers/certificates is a critical prerequisite for performing their job

Re: Firefox security too strict (HSTS?)?

2015-09-23 Thread R Kent James
On 9/23/2015 1:25 PM, Eric Mill wrote: Except in both of these cases -- removing TLS fallback to v1.0, and raising DH parameter minimums -- Chrome joined Firefox in doing so. Firefox went out first, and so that was the first impression people got, but Chrome's policies are no less strict. In at

Re: Policy Update Proposal: Remove Code Signing Trust Bit

2015-09-15 Thread R Kent James
of the Email trust bit? Is following this newsgroup sufficient? R. Kent James Chair, Thunderbird Council P.S. Various post-Snowden email security initiatives are now coming to a head, and this is likely to me a much-increased priority of Thunderbird in the future. We are currently talking about closely