Byron Clark wrote:

Is it possible to use GPG with Gmail, or any other web-based mail
service? If not, what purpose could it/does it server, other than cool
factor? If I use several computers, is it easy-ish to get my key onto
all of my accounts?




One reason I can see to not provide gpg for webmail services is that a
dishonest admin would have access to the private keys for every user.
So, make sure you trust the admins of any webservice that requires you
to store a private key on the server.

[1] https://mail.cs.byu.edu/squirrelmail/



------------------------------------------------------------------------

I use both CS and BYU mail. My understanding of what has been said so far is:

I can only use my pgp key on my home computer and any other computer I store my private key. I would have to be quite confident nobody with admin access (especially on compromised machines) or physical access (I've done data recovery plenty of times by plugging a drive into my computer and using root priveleges to get data) could get at my key. I suppose if I felt really confident I could implement Mike's SELinux and not worry as much about this sort of invasion.

To get around this I could upload my key to the cs computers, but then I would have to trust CS admins (which I don't; no offense, but I've seen prior abuse). So ultimately my key would only be attatched to mail I sent from home and be somewhat meaningless (since I don't have a Linode server set up).

Please correct me if I'm wrong

Scott K


--------------------
BYU Unix Users Group http://uug.byu.edu/


The opinions expressed in this message are the responsibility of their
author. They are not endorsed by BYU, the BYU CS Department or BYU-UUG. ___________________________________________________________________
List Info: http://uug.byu.edu/cgi-bin/mailman/listinfo/uug-list

Reply via email to