home bbs files messages ]

Just a sample of the Echomail archive

Cooperative anarchy at its finest, still active today. Darkrealms is the Zone 1 Hub.

   PUBLIC_KEYS      Public-Key Discussion Echo      845 messages   

[   << oldest   |   < older   |   list   |   newer >   |   newest >>   ]

   Message 774 of 845   
   August Abolins to Wilfred van Velzen   
   Safester, anyone?   
   31 Jan 22 01:20:00   
   
   MSGID: 2:221/1.58@fidonet f8f46308   
   REPLY: 2:280/464 61f56ba8   
   PID: OpenXP/5.0.51 (Win32)   
   CHRS: ASCII 1   
   TZUTC: -0500   
   Hello Wilfred!   
      
   ** On Saturday 29.01.22 - 17:24, you wrote to me:   
      
    AA>> However, it is somewhat astonishing that SHA-1 was/is   
    AA>> even used in the design.   
      
    WvV> Indeed. Which makes you question if they made other   
    WvV> mistakes.   
      
   Or.. purposeful compromises based on poor judgment.   
      
      
    AA>> In Safester, the decoded hash would reveal the   
    AA>> passphrase, but the decrypting of the messages would be   
    AA>> useless without the user's key which would reside in the   
    AA>> local Safester prog or app.   
      
    WvV> Well if your life depended on it, would you rather use   
    WvV> Safester or Opengpg?   
      
   Every email doesn't need to originate on the basis that my life     
   depended on it. But I get your point.  A journalist or a     
   reporter communicating a breaking story may like to steer away     
   from Safester, that's for sure.   
      
      
    WvV> The biggest drawback to me is you depend on a commercial   
    WvV> company for your secure mail. What if someone pays them a   
    WvV> big sum for being able to eavesdrop on your   
    WvV> conversations, will they make a backdoor? What if they go   
    WvV> bankrupt? Is your mail lost forever?   
      
   The backdoor matter is pretty cool. It would seem unethical,     
   but it's not unlike a locksmith's ability to unlock any door he     
   wants with a manufacturer's master key and get into your house.   
      
   Re: Bankrupt... all messages would certainly be *poof*.  In     
   that case, Protonmail, Startmail, Tutona would also fit in that     
   category. But those 3 seem to offer pop/smtp options inorder to     
   pull your mail off the servers.   
      
   However, Safester still seems like a good way to get people who     
   are opengpg-illiterate accustomed to appreciating private mail.   
      
   I am surprised how difficult it is to accomodate private mail     
   in iOS!  There are some free opengpg apps that come close to     
   working well, but those have been a frustrating experience for     
   a friend of mine. There is one app that he agreed to try (after     
   I sent him a $25 creditcard giftcard) for 1.99USD. ipgmail.      
   That one finally proved to be better than any of the free ones.     
   He's also testing Safester for a while longer too.   
   --   
     ../|ug   
   --- OpenXP 5.0.51   
    * Origin: Key ID = 0x5789589B (2:221/1.58)   
   SEEN-BY: 1/123 15/0 30/0 90/1 105/81 106/201 120/340 123/131 129/330   
   SEEN-BY: 129/331 153/7715 203/0 221/1 6 360 226/30 227/114 229/110   
   SEEN-BY: 229/206 317 400 424 426 664 700 240/1120 5832 266/512 280/464   
   SEEN-BY: 280/5003 282/1038 292/854 301/0 1 101 317/3 320/219 322/757   
   SEEN-BY: 342/200 396/45 423/81 460/58 712/848 5020/1042   
   PATH: 221/1 301/1 229/426   
      

[   << oldest   |   < older   |   list   |   newer >   |   newest >>   ]


(c) 1994,  bbs@darkrealms.ca