Re: [O] org-crypt.el security problem (From: Milan Zamazal)

2011-03-07 Thread Julien Danjou
On Sun, Mar 06 2011, Bastien wrote: >> What I can also suggest is to never show the encrypted block in the Org >> buffer. > > I agree this would be better. > >> This is what I do in my configuration: on Org file loading, I decrypt >> all entries. Therefore I never see the GPG block. When I save, >

Re: [O] org-crypt.el security problem (From: Milan Zamazal)

2011-03-06 Thread Bastien
Hi Julien, Julien Danjou writes: > What I can also suggest is to never show the encrypted block in the Org > buffer. I agree this would be better. > This is what I do in my configuration: on Org file loading, I decrypt > all entries. Therefore I never see the GPG block. When I save, > everythi

Re: [O] org-crypt.el security problem (From: Milan Zamazal)

2011-03-06 Thread Julien Danjou
On Sun, Mar 06 2011, Bastien wrote: > I've seen org-encrypt-string but I don't see we could use it for the > problem at hand. Just saying that if you don't use it, youe re-encryption on auto-save will ask the user for its passphrase if he is not using any agent. > Also, the purpose is to encr

Re: [O] org-crypt.el security problem (From: Milan Zamazal)

2011-03-06 Thread Bastien
Hi Julien, Julien Danjou writes: > On Fri, Mar 04 2011, Peter Jones wrote: > >> Hopefully there's an autosave hook where you can encrypt the headings >> and save to disk using a temporary buffer without having to alter the >> current buffer and interrupt the user by encrypting a heading that is

Re: [O] org-crypt.el security problem (From: Milan Zamazal)

2011-03-06 Thread Bastien
Hi Peter, Peter Jones writes: > Here is an email I received from Milan Zamazal: > > , > | I don't know whether you are aware of this, but I consider it a serious > | security problem of org-crypt.el in (at least) Emacs 23.2: > | > | I've found out that when I edit a (decrypted) crypt entry

Re: [O] org-crypt.el security problem (From: Milan Zamazal)

2011-03-04 Thread Julien Danjou
On Fri, Mar 04 2011, Peter Jones wrote: > Hopefully there's an autosave hook where you can encrypt the headings > and save to disk using a temporary buffer without having to alter the > current buffer and interrupt the user by encrypting a heading that is > being edited. I've recently added cachi

[O] org-crypt.el security problem (From: Milan Zamazal)

2011-03-04 Thread Peter Jones
Here is an email I received from Milan Zamazal: , | I don't know whether you are aware of this, but I consider it a serious | security problem of org-crypt.el in (at least) Emacs 23.2: | | I've found out that when I edit a (decrypted) crypt entry and the edited | file is autosaved, the autosa