Are you sure it's a flash problem ? It's seem realy imposible..

527

(2 replies, posted in General)

But it's shouldn't change anything for you.

> Checking encrypted contents (just think of SSL protected web pages and filtering proxies) has to be solved at the application level.

Yes. But we are after the application, who is the server who create the page, not the client.

> In general I would say that you try to care about a problem that is not yours.

Yes it's our problem. An Firefox extension has full rights (an extension can format your disk if she wants...), and use FireGPG to inject html is a problem wink.

Edit :

Ho btw, it's apply to webmail but we can't detect all webmail in the world. It's apply to forums too if it's apply to webmail. And blogs. And everything.

> That wouldn't make any difference to sending the same code unencrypted.

I don't agree, as this problem are (should) handle by system who have to, in my example yahoo.

FireGPG can't parse html to be secure in all different case, except if he simply remove all html and keep the text, only the text.

You said "href to a different domain". But href to the same domain are dangerous too. Imagine an <img src="delete.php?id=balbalba"> wink Edit : woops misunderstanding

Safe tags are only tags like <b>, <font>, etc. But we should handle unclosed tags, etc.. It's too works for a not very critical feature...

But notice we have to think on this problem. We have to (it's our #1 problem now) be able to parse mail in pgp/mine format. Who encrypt/sign mail at lower level that the mail content, so when we decrypt this kind of email, we (can) got html...

Problem : About security ?

If someone send a email to a yahoo user, using his private key. FireGPG autodecrypt the text, and re-insert it into the dom. Imagine the text contains javascript (XSS) or a image (tracking).

So it's seem to be a good idea but.. it not a good idea wink

531

(2 replies, posted in Bugs & problems)

(sorry you post was tagged as spam).

How you do verify it ?

532

(14 replies, posted in gpgAuth)

Hi,

I don't know wink

Regards,

533

(25 replies, posted in Bugs & problems)

Read the install page ,)

534

(25 replies, posted in Bugs & problems)

Hum, I don't know oO

535

(2 replies, posted in Bugs & problems)

Your content is not encrypted, he is signed.

I assume you wants to make a CLEAR sign to have to text still redable for a non-pgp user wink

Hi,

We know them and try to find ways to fix them wink

Regards,

537

(25 replies, posted in Bugs & problems)

Hi,

No, realy no !

Maybe Windows x86_64 ?

538

(1 replies, posted in Bugs & problems)

Read forum or bug tracker or news before report bugs...

539

(19 replies, posted in Requests)

Relatives paths planned wink

540

(1 replies, posted in Bugs & problems)

"please check the download page of firegpg"

...

And you don't need to send an email AND a post on the forum.

cups-pdf ? Because it's what I use and I haven't any crash...

Ok so it's the FireGPG fault.

Problems : 1) I haven't the problem (do you have a sample page ?) 2) For crash there is no ways to debug, except launch Firefox in a console.

Try :

- Run in a console and copy past last messages after the crash
- Disable all another extexion except FireGPG and try to crash.

What is your os and your firefox's version ?

Regards,

Try do disable FireGPG, we don't know wink

544

(1 replies, posted in Misc)

Hi,

Yes. If you use version 0.6.x.

Regards,

545

(3 replies, posted in New versions)

We can't do more than what is currently in place. FireFTP author is in vacations so... wait wink

546

(4 replies, posted in Requests)

Btw we have to reform the way to send mail - to be openpgp/mime compatible so...

Already planned.

548

(1 replies, posted in Requests)

Mokidoki

549

(18 replies, posted in Bugs & problems)

Problem is FireGPG to gnupg works perfectly...

0.6.3 just released maxxxcad wink