<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
	<channel>
		<title><![CDATA[FireGPG Forum - About gpgAuth]]></title>
		<link>http://forum.getfiregpg.org/viewtopic.php?id=159</link>
		<description><![CDATA[The most recent posts in About gpgAuth.]]></description>
		<lastBuildDate>Mon, 16 Mar 2009 16:17:02 +0000</lastBuildDate>
		<generator>PunBB</generator>
		<item>
			<title><![CDATA[Re: About gpgAuth]]></title>
			<link>http://forum.getfiregpg.org/viewtopic.php?pid=1973#p1973</link>
			<description><![CDATA[<p>The way I see it: I will remove a feature and receive 10 mails from angry users <img src="http://forum.getfiregpg.org/img/smilies/wink.png" width="15" height="15" alt="wink" /></p><p>&gt; Why not talk to each other and share notes at least ?</p><p>I&#039;m already too busy to develop firegpg, I won&#039;t begin to communicate with another person to develop some feature in common as I can&#039;t develop firegpg himself <img src="http://forum.getfiregpg.org/img/smilies/wink.png" width="15" height="15" alt="wink" /></p>]]></description>
			<author><![CDATA[dummy@example.com (the_glu)]]></author>
			<pubDate>Mon, 16 Mar 2009 16:17:02 +0000</pubDate>
			<guid>http://forum.getfiregpg.org/viewtopic.php?pid=1973#p1973</guid>
		</item>
		<item>
			<title><![CDATA[Re: About gpgAuth]]></title>
			<link>http://forum.getfiregpg.org/viewtopic.php?pid=1972#p1972</link>
			<description><![CDATA[<p>&gt; Why?</p><p>The way i see it: if a protocol has no active upstream support, no advocate, no formal specification, no development community, and no way of responding to reasonable concerns, then implementations of that protocol probably do not belong in a piece of user-facing security-critical software.&nbsp; At least not without big shiny red warning flags all around any and all UI related to where it might actually be used (and even that should only be possible after ticking a checkbox that can only be found in the bottom of a locked filing cabinet stuck in a disused lavatory with a sign on the door saying &#039;Beware of the Leopard&#039;) <img src="http://forum.getfiregpg.org/img/smilies/wink.png" width="15" height="15" alt="wink" /></p><p>&gt; No.</p><p>It seems like Enigform and FireGPG do some similar (though certainly not identical) tasks.&nbsp; They both do some incredible work behind the scenes to help Firefox talk to GnuPG, both potentially deal with Web of Trust issues, both ask the user for their GPG passphrase, and both deal with potential signing of sensitive data.&nbsp; Why not talk to each other and share notes at least?</p>]]></description>
			<author><![CDATA[dummy@example.com (dkg)]]></author>
			<pubDate>Mon, 16 Mar 2009 05:26:40 +0000</pubDate>
			<guid>http://forum.getfiregpg.org/viewtopic.php?pid=1972#p1972</guid>
		</item>
		<item>
			<title><![CDATA[Re: About gpgAuth]]></title>
			<link>http://forum.getfiregpg.org/viewtopic.php?pid=1971#p1971</link>
			<description><![CDATA[<p>&gt; perhaps support for gpgAuth should be dropped from FireGPG ?</p><p>Why ? Maybe he could be usefull <img src="http://forum.getfiregpg.org/img/smilies/wink.png" width="15" height="15" alt="wink" /></p><p>&gt; Are you guys in discussion with buanzo (the author of enigform) ?</p><p>No.</p>]]></description>
			<author><![CDATA[dummy@example.com (the_glu)]]></author>
			<pubDate>Mon, 16 Mar 2009 05:09:38 +0000</pubDate>
			<guid>http://forum.getfiregpg.org/viewtopic.php?pid=1971#p1971</guid>
		</item>
		<item>
			<title><![CDATA[Re: About gpgAuth]]></title>
			<link>http://forum.getfiregpg.org/viewtopic.php?pid=1970#p1970</link>
			<description><![CDATA[<p>I found <a href="http://foros.buanzo.com.ar/viewtopic.php?f=37&amp;t=231">a discussion on enigform&#039;s forum</a> that suggests that Kyle Huff (the original gpgAuth author) is proposing abandoning gpgAuth entirely in favor of enigform and apache&#039;s associated mod_auth_openpgp. <a href="http://foros.buanzo.com.ar/viewtopic.php?f=35&amp;t=263">another post suggests that he has in fact joined the enigform team</a> As such, i plan on moving my cryptographic review to that suite of tools, and suggest that people avoid using gpgAuth entirely unless more information is forthcoming.</p><p>If you don&#039;t know how to reach the gpgAuth author, and he seems to have abandoned his own project, perhaps support for gpgAuth should be dropped from FireGPG ?&nbsp; Are you guys in discussion with buanzo (the author of enigform) about the ways your respective tools could work together?</p>]]></description>
			<author><![CDATA[dummy@example.com (dkg)]]></author>
			<pubDate>Mon, 16 Mar 2009 02:48:47 +0000</pubDate>
			<guid>http://forum.getfiregpg.org/viewtopic.php?pid=1970#p1970</guid>
		</item>
		<item>
			<title><![CDATA[Re: About gpgAuth]]></title>
			<link>http://forum.getfiregpg.org/viewtopic.php?pid=1969#p1969</link>
			<description><![CDATA[<p>Thanks for your quick followup, the_glu.&nbsp; If i find anything out that&#039;s relevant to firegpg, i&#039;ll post it here.</p>]]></description>
			<author><![CDATA[dummy@example.com (dkg)]]></author>
			<pubDate>Sun, 15 Mar 2009 22:32:40 +0000</pubDate>
			<guid>http://forum.getfiregpg.org/viewtopic.php?pid=1969#p1969</guid>
		</item>
		<item>
			<title><![CDATA[Re: About gpgAuth]]></title>
			<link>http://forum.getfiregpg.org/viewtopic.php?pid=1968#p1968</link>
			<description><![CDATA[<p>&gt; do you have another way i should contact him or her? </p><p>No</p><p>&gt; can you explain more about why that wouldn&#039;t be a risk for users of firegpg?</p><p>They have to confirm any gpgauth action <img src="http://forum.getfiregpg.org/img/smilies/wink.png" width="15" height="15" alt="wink" /></p>]]></description>
			<author><![CDATA[dummy@example.com (the_glu)]]></author>
			<pubDate>Sun, 15 Mar 2009 21:28:46 +0000</pubDate>
			<guid>http://forum.getfiregpg.org/viewtopic.php?pid=1968#p1968</guid>
		</item>
		<item>
			<title><![CDATA[Re: About gpgAuth]]></title>
			<link>http://forum.getfiregpg.org/viewtopic.php?pid=1967#p1967</link>
			<description><![CDATA[<p>I&#039;ve tried to contact the author by posting on the forum, but didn .&nbsp; do you have another way i should contact him or her?&nbsp; whois suggests that he&#039;s named &quot;kyle huff&quot;, but the main kyle huffs i found online was someone who went on shooting rampage in seattle a few years ago <img src="http://forum.getfiregpg.org/img/smilies/sad.png" width="15" height="15" alt="sad" /> </p><p>And i&#039;m concerned not just that gpgauth is spoofable (i wouldn&#039;t trust it anyway), but that gpgauth support in firegpg could potentially allow for abuse of the user&#039;s keyring by a remote server which prompts for gpgauth activity.</p><p>can you explain more about why that wouldn&#039;t be a risk for users of firegpg?</p>]]></description>
			<author><![CDATA[dummy@example.com (dkg)]]></author>
			<pubDate>Sun, 15 Mar 2009 21:05:14 +0000</pubDate>
			<guid>http://forum.getfiregpg.org/viewtopic.php?pid=1967#p1967</guid>
		</item>
		<item>
			<title><![CDATA[Re: About gpgAuth]]></title>
			<link>http://forum.getfiregpg.org/viewtopic.php?pid=1963#p1963</link>
			<description><![CDATA[<p>Hi,</p><p>I&#039;m not the auther of gpgauth, and if there is any security problem with gpgauth, it&#039;s wont affect the rest of firegpg <img src="http://forum.getfiregpg.org/img/smilies/wink.png" width="15" height="15" alt="wink" /></p><p>I sugest you to contact the author of gpgAuth <img src="http://forum.getfiregpg.org/img/smilies/wink.png" width="15" height="15" alt="wink" /></p>]]></description>
			<author><![CDATA[dummy@example.com (the_glu)]]></author>
			<pubDate>Fri, 13 Mar 2009 21:34:13 +0000</pubDate>
			<guid>http://forum.getfiregpg.org/viewtopic.php?pid=1963#p1963</guid>
		</item>
		<item>
			<title><![CDATA[Re: About gpgAuth]]></title>
			<link>http://forum.getfiregpg.org/viewtopic.php?pid=1962#p1962</link>
			<description><![CDATA[<p>I recently raised <a href="http://www.gpgauth.com/forums/index.php?topic=3.msg6">significant problems and concerns with the gpgauth protocol</a> on the gpgauth forums, and only got a response from someone who does not appear to be an author of the site.</p><p>Is fireGPG&#039;s gpgauth support vulnerable to the concerns i raised there?</p>]]></description>
			<author><![CDATA[dummy@example.com (dkg)]]></author>
			<pubDate>Fri, 13 Mar 2009 21:11:47 +0000</pubDate>
			<guid>http://forum.getfiregpg.org/viewtopic.php?pid=1962#p1962</guid>
		</item>
		<item>
			<title><![CDATA[Re: About gpgAuth]]></title>
			<link>http://forum.getfiregpg.org/viewtopic.php?pid=1436#p1436</link>
			<description><![CDATA[<p>Hi,</p><p>I don&#039;t know <img src="http://forum.getfiregpg.org/img/smilies/wink.png" width="15" height="15" alt="wink" /></p><p>Regards,</p>]]></description>
			<author><![CDATA[dummy@example.com (the_glu)]]></author>
			<pubDate>Sat, 29 Nov 2008 06:36:31 +0000</pubDate>
			<guid>http://forum.getfiregpg.org/viewtopic.php?pid=1436#p1436</guid>
		</item>
		<item>
			<title><![CDATA[Re: About gpgAuth]]></title>
			<link>http://forum.getfiregpg.org/viewtopic.php?pid=1435#p1435</link>
			<description><![CDATA[<p>Hello,</p><p>Tried to follow the links to both the GPGauth write-up and the gpgauth.com site, but both links appear broken.</p><p>What is the current status with GPGauth and where can I find the latest GPGauth-related code and docs?</p><p>Thanks in advance,</p><p>Eva</p>]]></description>
			<author><![CDATA[dummy@example.com (Eva)]]></author>
			<pubDate>Sat, 29 Nov 2008 03:22:22 +0000</pubDate>
			<guid>http://forum.getfiregpg.org/viewtopic.php?pid=1435#p1435</guid>
		</item>
		<item>
			<title><![CDATA[Re: About gpgAuth]]></title>
			<link>http://forum.getfiregpg.org/viewtopic.php?pid=1064#p1064</link>
			<description><![CDATA[<div class="quotebox"><cite>sbkolluru wrote:</cite><blockquote><p>How to add the plug in firegpg.xpi to firefox bowser?</p></blockquote></div><p>Just drag it into a firefox window....</p>]]></description>
			<author><![CDATA[dummy@example.com (Faramir.cl)]]></author>
			<pubDate>Sun, 11 May 2008 20:07:08 +0000</pubDate>
			<guid>http://forum.getfiregpg.org/viewtopic.php?pid=1064#p1064</guid>
		</item>
		<item>
			<title><![CDATA[Re: About gpgAuth]]></title>
			<link>http://forum.getfiregpg.org/viewtopic.php?pid=931#p931</link>
			<description><![CDATA[<p>Did&#039;t understand.</p>]]></description>
			<author><![CDATA[dummy@example.com (the_glu)]]></author>
			<pubDate>Tue, 05 Feb 2008 16:01:20 +0000</pubDate>
			<guid>http://forum.getfiregpg.org/viewtopic.php?pid=931#p931</guid>
		</item>
		<item>
			<title><![CDATA[Re: About gpgAuth]]></title>
			<link>http://forum.getfiregpg.org/viewtopic.php?pid=930#p930</link>
			<description><![CDATA[<p>How to add the plug in firegpg.xpi to firefox bowser?</p>]]></description>
			<author><![CDATA[dummy@example.com (sbkolluru)]]></author>
			<pubDate>Tue, 05 Feb 2008 13:46:39 +0000</pubDate>
			<guid>http://forum.getfiregpg.org/viewtopic.php?pid=930#p930</guid>
		</item>
		<item>
			<title><![CDATA[About gpgAuth]]></title>
			<link>http://forum.getfiregpg.org/viewtopic.php?pid=563#p563</link>
			<description><![CDATA[<div class="quotebox"><blockquote><p>We have posted a write-up that talks about what gpgAuth is and how it works.&nbsp; You can visit it here: <a href="http://www.gpgauth.com/#what_how">http://www.gpgauth.com/#what_how</a></p><p>We are working on getting a writeup that explains how to implement it. It should be available sometime Monday, June 25th, 2007.</p><p>The forums are open now as well, so feel free to ask some questions.</p><p>The gpgAuth Team - <a href="http://www.gpgauth.com">www.gpgauth.com</a></p></blockquote></div>]]></description>
			<author><![CDATA[dummy@example.com (the_glu)]]></author>
			<pubDate>Sun, 24 Jun 2007 19:07:01 +0000</pubDate>
			<guid>http://forum.getfiregpg.org/viewtopic.php?pid=563#p563</guid>
		</item>
	</channel>
</rss>
