Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > alt.os.linux > #50877 > unrolled thread

Good example why business emails should be PGP'ed

Started byFritz Wuehler <fritz@spamexpire-201809.rodent.frell.theremailer.net>
First post2018-09-23 19:45 +0000
Last post2018-09-24 08:37 -0700
Articles 20 on this page of 35 — 11 participants

Back to article view | Back to alt.os.linux


Contents

  Good example why business emails should be PGP'ed Fritz Wuehler <fritz@spamexpire-201809.rodent.frell.theremailer.net> - 2018-09-23 19:45 +0000
    Re: Good example why business emails should be PGP'ed "Carlos E. R." <robin_listas@es.invalid> - 2018-09-23 22:03 -0400
      Re: Good example why business emails should be PGP'ed Dan Purgert <dan@djph.net> - 2018-09-24 10:27 +0000
        Re: Good example why business emails should be PGP'ed Richard Kettlewell <invalid@invalid.invalid> - 2018-09-24 14:11 +0100
          Re: Good example why business emails should be PGP'ed Dan Purgert <dan@djph.net> - 2018-09-24 15:20 +0000
            Re: Good example why business emails should be PGP'ed Richard Kettlewell <invalid@invalid.invalid> - 2018-09-24 17:49 +0100
        Re: Good example why business emails should be PGP'ed Grant Taylor <gtaylor@tnetconsulting.net> - 2018-09-24 09:57 -0600
          Re: Good example why business emails should be PGP'ed Dan Purgert <dan@djph.net> - 2018-09-24 16:40 +0000
      Re: Good example why business emails should be PGP'ed anon <noreply@mixnym.net> - 2018-09-24 07:48 -0500
        Re: Good example why business emails should be PGP'ed "Carlos E. R." <robin_listas@es.invalid> - 2018-09-24 13:18 -0400
          Re: Good example why business emails should be PGP'ed anon <noreply@mixnym.net> - 2018-09-25 08:16 -0500
            Re: Good example why business emails should be PGP'ed "Carlos E. R." <robin_listas@es.invalid> - 2018-09-25 10:26 -0400
              Re: Good example why business emails should be PGP'ed Wouter Verhelst <w@uter.be> - 2018-09-25 17:17 +0200
                Re: Good example why business emails should be PGP'ed "Carlos E. R." <robin_listas@es.invalid> - 2018-09-26 14:16 -0400
                  Re: Good example why business emails should be PGP'ed nospam <nospam@nospam.invalid> - 2018-09-26 14:24 -0400
                    Re: Good example why business emails should be PGP'ed "Carlos E. R." <robin_listas@es.invalid> - 2018-09-26 14:47 -0400
                      Re: Good example why business emails should be PGP'ed nospam <nospam@nospam.invalid> - 2018-09-26 14:56 -0400
                        Re: Good example why business emails should be PGP'ed "Carlos E. R." <robin_listas@es.invalid> - 2018-09-26 22:20 -0400
                          Re: Good example why business emails should be PGP'ed nospam <nospam@nospam.invalid> - 2018-09-27 00:43 -0400
                            Re: Good example why business emails should be PGP'ed "Carlos E. R." <robin_listas@es.invalid> - 2018-09-27 11:21 -0400
                              Re: Good example why business emails should be PGP'ed nospam <nospam@nospam.invalid> - 2018-09-27 11:52 -0400
                                Re: Good example why business emails should be PGP'ed "Carlos E. R." <robin_listas@es.invalid> - 2018-09-27 12:10 -0400
                                  Re: Good example why business emails should be PGP'ed nospam <nospam@nospam.invalid> - 2018-09-27 12:15 -0400
                                    Re: Good example why business emails should be PGP'ed "Carlos E. R." <robin_listas@es.invalid> - 2018-09-27 14:31 -0400
                                      Re: Good example why business emails should be PGP'ed Frank Slootweg <this@ddress.is.invalid> - 2018-09-27 20:07 +0000
                                        Re: Good example why business emails should be PGP'ed nospam <nospam@nospam.invalid> - 2018-09-27 16:39 -0400
                                          Re: Good example why business emails should be PGP'ed "Carlos E. R." <robin_listas@es.invalid> - 2018-09-28 09:45 -0400
                                            Re: Good example why business emails should be PGP'ed nospam <nospam@nospam.invalid> - 2018-09-28 09:52 -0400
                                              Re: Good example why business emails should be PGP'ed "Carlos E. R." <robin_listas@es.invalid> - 2018-09-28 14:22 -0400
                                                Re: Good example why business emails should be PGP'ed nospam <nospam@nospam.invalid> - 2018-09-28 14:26 -0400
                                                  Re: Good example why business emails should be PGP'ed "Carlos E. R." <robin_listas@es.invalid> - 2018-09-28 15:43 -0400
                                                    Re: Good example why business emails should be PGP'ed nospam <nospam@nospam.invalid> - 2018-09-28 15:54 -0400
                          Re: Good example why business emails should be PGP'ed The Natural Philosopher <tnp@invalid.invalid> - 2018-09-27 06:52 +0100
                            Re: Good example why business emails should be PGP'ed "Carlos E. R." <robin_listas@es.invalid> - 2018-09-27 11:22 -0400
    Re: Good example why business emails should be PGP'ed Mike Easter <MikeE@ster.invalid> - 2018-09-24 08:37 -0700

Page 1 of 2  [1] 2  Next page →


#50877 — Good example why business emails should be PGP'ed

FromFritz Wuehler <fritz@spamexpire-201809.rodent.frell.theremailer.net>
Date2018-09-23 19:45 +0000
SubjectGood example why business emails should be PGP'ed
Message-ID<309a76cf8bed5568f4d87d680befa055@msgid.frell.theremailer.net>
Hackers target real estate deals, with devastating impact

<https://www.yahoo.com/news/hackers-target-real-estate-deals-devastating-impact-015558592.html>

  Here is a very simple PGP client that will automatically set itself up and is simple to use.  You should insist a company you are dealing with uses PGP.  I refused to buy precious metals once from a company because they wouldn't communicate with me using PGP.  They were foolishly fearful that the IRS would think they were doing something illegal.  So they opened their customers to being revealed and endangered.

https://sourceforge.net/projects/gentlegpg/


Some other:

https://www.gpg4win.org/
https://sourceforge.net/projects/ppgp/

[toc] | [next] | [standalone]


#50881

From"Carlos E. R." <robin_listas@es.invalid>
Date2018-09-23 22:03 -0400
Message-ID<g0quv3Fhk7dU1@mid.individual.net>
In reply to#50877
On 23/09/2018 15.45, Fritz Wuehler wrote:
> Hackers target real estate deals, with devastating impact
> 
> <https://www.yahoo.com/news/hackers-target-real-estate-deals-devastating-impact-015558592.html>
>


«...and at closing time wired $272,000 from their bank following
instructions they received by email.

Within hours, the money had vanished.

Unbeknownst to the Colorado couple, the email account for the real
estate settlement company had been hacked, and fraudsters had altered
the wiring instruction to make off with the hefty sum representing a big
chunk of the Butchers' life savings, according to a lawsuit filed in
state court.»


>   Here is a very simple PGP client that will automatically set itself up and is simple to use.  You should insist a company you are dealing with uses PGP.  I refused to buy precious metals once from a company because they wouldn't communicate with me using PGP.  They were foolishly fearful that the IRS would think they were doing something illegal.  So they opened their customers to being revealed and endangered.
> 

PGPG, huh?

And how would you know that the PGP public key you have is in fact the
key of the correct real state agency, and not of some other "person"?
How are you going to ensure the proper chain of trust, hein?

That's assuming that the hackers don't have control of the agency computer.

> https://sourceforge.net/projects/gentlegpg/
> 
> 
> Some other:
> 
> https://www.gpg4win.org/
> https://sourceforge.net/projects/ppgp/
> 
> 


-- 
Cheers,
       Carlos E.R.

[toc] | [prev] | [next] | [standalone]


#50888

FromDan Purgert <dan@djph.net>
Date2018-09-24 10:27 +0000
Message-ID<slrnpqhf19.6s3.dan@xps-linux.djph.net>
In reply to#50881
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Carlos E. R. wrote:
> On 23/09/2018 15.45, Fritz Wuehler wrote:
>> Hackers target real estate deals, with devastating impact
>> 
>>
>>   Here is a very simple PGP client that will automatically set itself
>>   up and is simple to use.  You should insist a company you are
>>   dealing with uses PGP.  I refused to buy precious metals once from
>>   a company because they wouldn't communicate with me using PGP.
>>   They were foolishly fearful that the IRS would think they were
>>   doing something illegal.  So they opened their customers to being
>>   revealed and endangered.
>> 
>
> PGPG, huh?
>
> And how would you know that the PGP public key you have is in fact the
> key of the correct real state agency, and not of some other "person"?
> How are you going to ensure the proper chain of trust, hein?

PGP uses the "Web of Trust" model, rather than the x.509 "Chain of
Trust", but it does rely on you trusting people who in turn trust the
signer's key.  For example, none of you likely trust the signature on
this message very far :).

>
> That's assuming that the hackers don't have control of the agency
> computer.
>

To be fair, that's the same problem with S/MIME -- no telling whether or
not the machine itself was compromised.

Honestly, the best way around that is physical -- i.e. "come down to the
office and ..."; rather than acting on instructions received via
electronic means (in fact, that's how several businesses I interact with
are - you either have to walk into their office, or use the phone
[although phone instructions can be rejected if they're "doing too
much"]).


-----BEGIN PGP SIGNATURE-----

iQEzBAEBCAAdFiEEBcqaUD8uEzVNxUrujhHd8xJ5ooEFAluou9EACgkQjhHd8xJ5
ooEZiQgAmBnE2KSt2BlN04B5dkN9rVPXBzK1j/qRxod827zwJS7q8a9XFsl5EPAp
CdczrxZrurY/dPAVIzjLfIqG1Xrn5bCQR7bYK78Z7qSlMdwJzYjDQrTmM/2pU4tg
+oBwsk2dlcbTGIqZzEwsdBxnDoCxvTbOqlrnNIeyml2Tl9MoWJ0h9y3KC1S6WRGn
8j8eGB+S/jMl7ajEis9L5bnBPz2pPziHlFXw7TUUnxbLxR4803ufQ84I3Hh+FrzL
8lvFFkPGpnSAJwcJuM6Kj21IlwpW9nyIB+2tTpOsSFGjZzpmnVkNODdjLlUASSvT
2EbkRrDvvNCeukhZx8HkHwBWQlPPAw==
=fuaJ
-----END PGP SIGNATURE-----

-- 
|_|O|_| Registered Linux user #585947
|_|_|O| Github: https://github.com/dpurgert
|O|O|O| PGP: 05CA 9A50 3F2E 1335 4DC5  4AEE 8E11 DDF3 1279 A281

[toc] | [prev] | [next] | [standalone]


#50895

FromRichard Kettlewell <invalid@invalid.invalid>
Date2018-09-24 14:11 +0100
Message-ID<87d0t3kplb.fsf@LkoBDZeT.terraraq.uk>
In reply to#50888
Dan Purgert <dan@djph.net> writes:
> Carlos E. R. wrote:
>> And how would you know that the PGP public key you have is in fact the
>> key of the correct real state agency, and not of some other "person"?
>> How are you going to ensure the proper chain of trust, hein?
>
> PGP uses the "Web of Trust" model, rather than the x.509 "Chain of
> Trust", but it does rely on you trusting people who in turn trust the
> signer's key.  For example, none of you likely trust the signature on
> this message very far :).

Aside from the key management, and the obsolete crypto, PGP’s problem
for mainstream business-to-consumer use is that the usability is
dreadful.

>> That's assuming that the hackers don't have control of the agency
>> computer.
>
> To be fair, that's the same problem with S/MIME -- no telling whether or
> not the machine itself was compromised.
>
> Honestly, the best way around that is physical -- i.e. "come down to the
> office and ..."; rather than acting on instructions received via
> electronic means (in fact, that's how several businesses I interact with
> are - you either have to walk into their office, or use the phone
> [although phone instructions can be rejected if they're "doing too
> much"]).

That’s what my conveyancing solicitor does. Payment details are
communicated on paper at their office, with strict instructions to
disregard any electronic communications.

-- 
https://www.greenend.org.uk/rjk/

[toc] | [prev] | [next] | [standalone]


#50896

FromDan Purgert <dan@djph.net>
Date2018-09-24 15:20 +0000
Message-ID<slrnpqi054.6s3.dan@xps-linux.djph.net>
In reply to#50895
Richard Kettlewell wrote:
> [...]
> Aside from the key management, and the obsolete crypto, PGP’s problem
> for mainstream business-to-consumer use is that the usability is
> dreadful.

Obsolete crypto?  Doesn't PGP / GPG use the AES cipher under the hood?
I mean, the default is pretty bad, but... 

And yeah, I'm hardly advocating consumers use it.  It's bad enough
dealing with "the email didn't work" when it's plaintext :)


-- 
|_|O|_| Registered Linux user #585947
|_|_|O| Github: https://github.com/dpurgert
|O|O|O| PGP: 05CA 9A50 3F2E 1335 4DC5  4AEE 8E11 DDF3 1279 A281

[toc] | [prev] | [next] | [standalone]


#50906

FromRichard Kettlewell <invalid@invalid.invalid>
Date2018-09-24 17:49 +0100
Message-ID<877ejalu1n.fsf@LkoBDZeT.terraraq.uk>
In reply to#50896
Dan Purgert <dan@djph.net> writes:
> Richard Kettlewell wrote:
>> Aside from the key management, and the obsolete crypto, PGP’s problem
>> for mainstream business-to-consumer use is that the usability is
>> dreadful.
>
> Obsolete crypto?  Doesn't PGP / GPG use the AES cipher under the hood?
> I mean, the default is pretty bad, but...

There’s more to security than choice of block cipher.

In this case, the specific problem is that PGP has a poorly designed
integrity check (or in some cases _no_ integrity check) on the
ciphertext, allowing a variety of attacks exploiting ciphertext
malleability.

The general issues have been understood for a long time (I think since
last century), and PGP’s poor response (and S/MIME’s non-response) are
effectively exploited in https://efail.de/efail-attack-paper.pdf.

-- 
https://www.greenend.org.uk/rjk/

[toc] | [prev] | [next] | [standalone]


#50900

FromGrant Taylor <gtaylor@tnetconsulting.net>
Date2018-09-24 09:57 -0600
Message-ID<pob1v4$udi$1@tncsrv09.home.tnetconsulting.net>
In reply to#50888
On 09/24/2018 04:27 AM, Dan Purgert wrote:
> PGP uses the "Web of Trust" model, rather than the x.509 "Chain of 
> Trust", but it does rely on you trusting people who in turn trust the 
> signer's key.  For example, none of you likely trust the signature on 
> this message very far :).

That's one way to use PGP.  Another is to exchange public key signatures 
/ hashes via Out of Band methods with the party in question.

That is completely independent of the web of trust or chain of trust model.

The same can be done with S/MIME.

> To be fair, that's the same problem with S/MIME -- no telling whether 
> or not the machine itself was compromised.

IMHO neither PGP nor S/MIME are meant to defend against a compromised 
machine.  -  If you're worried about that, you have bigger issues.

Also, both PGP / S/MIME do a LOT to offer security & integrity to 
communications that otherwise wouldn't have it.  I'm not saying that 
it's great.  I am saying that it's better than the alternative, be it 
plaintext or no text at all.

> Honestly, the best way around that is physical -- i.e. "come down to 
> the office and ...";

You don't have to conduct all transactions in person.  That's also 
subject to disguises.

You need to establish a seed of trust in person (or over the phone) and 
then use that seed of trust for remote communications.

I say over the phone because I've done so with multiple friends as we 
started using S/MIME.  We knew each others phone numbers, we knew how 
each other would respond, we recognized each others voices.  So if 
someone (state actor or otherwise) can (wo)man-in-the-middle that phone 
call at the proper time, disguising their voice, well, they've got my 
friends and I.

> rather than acting on instructions received via electronic means (in fact, 
> that's how several businesses I interact with are - you either have to 
> walk into their office, or use the phone [although phone instructions 
> can be rejected if they're "doing too much"]).

IMHO it's better to establish a seed of trust that can easily be 
leveraged remotely to provide better security and enable remote 
transactions.



-- 
Grant. . . .
unix || die

[toc] | [prev] | [next] | [standalone]


#50905

FromDan Purgert <dan@djph.net>
Date2018-09-24 16:40 +0000
Message-ID<slrnpqi4rm.6s3.dan@xps-linux.djph.net>
In reply to#50900
Grant Taylor wrote:
> On 09/24/2018 04:27 AM, Dan Purgert wrote:
>> PGP uses the "Web of Trust" model, rather than the x.509 "Chain of 
>> Trust", but it does rely on you trusting people who in turn trust the 
>> signer's key.  For example, none of you likely trust the signature on 
>> this message very far :).
>
> That's one way to use PGP.  Another is to exchange public key signatures 
> / hashes via Out of Band methods with the party in question.

Oh right, forgot about that one this morning.

>
>> To be fair, that's the same problem with S/MIME -- no telling whether 
>> or not the machine itself was compromised.
>
> IMHO neither PGP nor S/MIME are meant to defend against a compromised 
> machine.  -  If you're worried about that, you have bigger issues.

Indeed.

> [...]
>> Honestly, the best way around that is physical -- i.e. "come down to 
>> the office and ...";
>
> You don't have to conduct all transactions in person.  That's also 
> subject to disguises.
>
> You need to establish a seed of trust in person (or over the phone) and 
> then use that seed of trust for remote communications.

Yeah, I never said that physical was the *only* way to conduct business.

> [...]
>> rather than acting on instructions received via electronic means (in fact, 
>> that's how several businesses I interact with are - you either have to 
>> walk into their office, or use the phone [although phone instructions 
>> can be rejected if they're "doing too much"]).
>
> IMHO it's better to establish a seed of trust that can easily be 
> leveraged remotely to provide better security and enable remote 
> transactions.

Oh, the businesses do both - but they only extend the "seed of
trust(tm)" so far.  Like my finance/ insurance people will accept a lot
of instructions over the phone; but "hey, I need to put >$10k into
$account" is a "we can't do that over the phone" transaction.

Realistically, that *might* be banking regulations moreso than anything,
never thought to dig into it further (because, let's face it, if I have
$10k to be moving around in one go, I probably have a lot of other
paperwork to fill out).


-- 
|_|O|_| Registered Linux user #585947
|_|_|O| Github: https://github.com/dpurgert
|O|O|O| PGP: 05CA 9A50 3F2E 1335 4DC5  4AEE 8E11 DDF3 1279 A281

[toc] | [prev] | [next] | [standalone]


#50893

Fromanon <noreply@mixnym.net>
Date2018-09-24 07:48 -0500
Message-ID<poamea$asa$1@news.mixmin.net>
In reply to#50881
Carlos E. R. was thinking very hard :
> On 23/09/2018 15.45, Fritz Wuehler wrote:
>> Hackers target real estate deals, with devastating impact
>> 
>> <https://www.yahoo.com/news/hackers-target-real-estate-deals-devastating-impact-015558592.html>
>> 
>
>
> «...and at closing time wired $272,000 from their bank following
> instructions they received by email.
>
> Within hours, the money had vanished.
>
> Unbeknownst to the Colorado couple, the email account for the real
> estate settlement company had been hacked, and fraudsters had altered
> the wiring instruction to make off with the hefty sum representing a 
> big chunk of the Butchers' life savings, according to a lawsuit filed 
> in state court.»
>
>
>>   Here is a very simple PGP client that will automatically set 
>> itself up and is simple to use.  You should insist a company you are 
>> dealing with uses PGP.  I refused to buy precious metals once from a 
>> company because they wouldn't communicate with me using PGP.  They 
>> were foolishly fearful that the IRS would think they were doing 
>> something illegal.  So they opened their customers to being revealed 
>> and endangered.
>> 
>
> PGPG, huh?
>
> And how would you know that the PGP public key you have is in fact 
> the key of the correct real state agency, and not of some other 
> "person"? How are you going to ensure the proper chain of trust, 
> hein?
>
> That's assuming that the hackers don't have control of the agency 
> computer.
>
>> https://sourceforge.net/projects/gentlegpg/
>> 
>> 
>> Some other:
>> 
>> https://www.gpg4win.org/
>> https://sourceforge.net/projects/ppgp/
>> 
>> 

  Key are signed.  You have to get their pgp public key from the 
company also.  You need to also verify a company's key through their 
key ID.  You could go on and on in fantizing problems and decide to do 
nothing.  Nota good path when it comes to security.  The suggestion 
above about only dealing directly with a company office is actually the 
best thing to do, but a local office may not be available.  But your 
defeatism is not the answer.

[toc] | [prev] | [next] | [standalone]


#50909

From"Carlos E. R." <robin_listas@es.invalid>
Date2018-09-24 13:18 -0400
Message-ID<g0skjkFs60rU1@mid.individual.net>
In reply to#50893
On 24/09/2018 08.48, anon wrote:
> Carlos E. R. was thinking very hard :
>> On 23/09/2018 15.45, Fritz Wuehler wrote:
>>> Hackers target real estate deals, with devastating impact
>>>
>>> <https://www.yahoo.com/news/hackers-target-real-estate-deals-devastating-impact-015558592.html>
>>>
>>>
>>
>>
>> «...and at closing time wired $272,000 from their bank following
>> instructions they received by email.
>>
>> Within hours, the money had vanished.
>>
>> Unbeknownst to the Colorado couple, the email account for the real
>> estate settlement company had been hacked, and fraudsters had altered
>> the wiring instruction to make off with the hefty sum representing a
>> big chunk of the Butchers' life savings, according to a lawsuit filed
>> in state court.»
>>
>>
>>>   Here is a very simple PGP client that will automatically set itself
>>> up and is simple to use.  You should insist a company you are dealing
>>> with uses PGP.  I refused to buy precious metals once from a company
>>> because they wouldn't communicate with me using PGP.  They were
>>> foolishly fearful that the IRS would think they were doing something
>>> illegal.  So they opened their customers to being revealed and
>>> endangered.
>>>
>>
>> PGPG, huh?
>>
>> And how would you know that the PGP public key you have is in fact the
>> key of the correct real state agency, and not of some other "person"?
>> How are you going to ensure the proper chain of trust, hein?
>>
>> That's assuming that the hackers don't have control of the agency
>> computer.
>>
>>> https://sourceforge.net/projects/gentlegpg/
>>>
>>>
>>> Some other:
>>>
>>> https://www.gpg4win.org/
>>> https://sourceforge.net/projects/ppgp/
>>>
>>>
> 
>  Key are signed.

By whom?

You need to walk to the company first, in person, and exchange keys. And
then make sure not to download other keys and not to trust the web of
trust, because you do not control who signs what.

I know quite well PGP, I use it, and it is not going to work for business.

-- 
Cheers,
       Carlos E.R.

[toc] | [prev] | [next] | [standalone]


#50924

Fromanon <noreply@mixnym.net>
Date2018-09-25 08:16 -0500
Message-ID<podcge$9e1$1@news.mixmin.net>
In reply to#50909
Carlos E. R. pretended :
> On 24/09/2018 08.48, anon wrote:
>> Carlos E. R. was thinking very hard :
>>> On 23/09/2018 15.45, Fritz Wuehler wrote:
>>>> Hackers target real estate deals, with devastating impact
>>>> 
>>>> <https://www.yahoo.com/news/hackers-target-real-estate-deals-devastating-impact-015558592.html>
>>>> 
>>>> 
>>> 
>>> 
>>> «...and at closing time wired $272,000 from their bank following
>>> instructions they received by email.
>>> 
>>> Within hours, the money had vanished.
>>> 
>>> Unbeknownst to the Colorado couple, the email account for the real
>>> estate settlement company had been hacked, and fraudsters had 
>>> altered the wiring instruction to make off with the hefty sum 
>>> representing a big chunk of the Butchers' life savings, according 
>>> to a lawsuit filed in state court.»
>>> 
>>> 
>>>>   Here is a very simple PGP client that will automatically set 
>>>> itself up and is simple to use.  You should insist a company you 
>>>> are dealing with uses PGP.  I refused to buy precious metals once 
>>>> from a company because they wouldn't communicate with me using 
>>>> PGP.  They were foolishly fearful that the IRS would think they 
>>>> were doing something illegal.  So they opened their customers to 
>>>> being revealed and endangered.
>>>> 
>>> 
>>> PGPG, huh?
>>> 
>>> And how would you know that the PGP public key you have is in fact 
>>> the key of the correct real state agency, and not of some other 
>>> "person"? How are you going to ensure the proper chain of trust, 
>>> hein?
>>> 
>>> That's assuming that the hackers don't have control of the agency
>>> computer.
>>> 
>>>> https://sourceforge.net/projects/gentlegpg/
>>>> 
>>>> 
>>>> Some other:
>>>> 
>>>> https://www.gpg4win.org/
>>>> https://sourceforge.net/projects/ppgp/
>>>> 
>>>> 
>> 
>>  Key are signed.
>
> By whom?
>
> You need to walk to the company first, in person, and exchange keys. 
> And then make sure not to download other keys and not to trust the 
> web of trust, because you do not control who signs what.
>
> I know quite well PGP, I use it, and it is not going to work for 
> business.

  So do nothing, PLEASE!  My your fall be great and embittering!

[toc] | [prev] | [next] | [standalone]


#50928

From"Carlos E. R." <robin_listas@es.invalid>
Date2018-09-25 10:26 -0400
Message-ID<g0uusnFc6hmU2@mid.individual.net>
In reply to#50924
On 25/09/2018 09.16, anon wrote:
> Carlos E. R. pretended :
>> On 24/09/2018 08.48, anon wrote:
>>> Carlos E. R. was thinking very hard :
>>>> On 23/09/2018 15.45, Fritz Wuehler wrote:
>>>>> Hackers target real estate deals, with devastating impact
>>>>>
>>>>> <https://www.yahoo.com/news/hackers-target-real-estate-deals-devastating-impact-015558592.html>
>>>>>
>>>>>
>>>>>
>>>>
>>>>
>>>> «...and at closing time wired $272,000 from their bank following
>>>> instructions they received by email.
>>>>
>>>> Within hours, the money had vanished.
>>>>
>>>> Unbeknownst to the Colorado couple, the email account for the real
>>>> estate settlement company had been hacked, and fraudsters had
>>>> altered the wiring instruction to make off with the hefty sum
>>>> representing a big chunk of the Butchers' life savings, according to
>>>> a lawsuit filed in state court.»
>>>>
>>>>
>>>>>   Here is a very simple PGP client that will automatically set
>>>>> itself up and is simple to use.  You should insist a company you
>>>>> are dealing with uses PGP.  I refused to buy precious metals once
>>>>> from a company because they wouldn't communicate with me using
>>>>> PGP.  They were foolishly fearful that the IRS would think they
>>>>> were doing something illegal.  So they opened their customers to
>>>>> being revealed and endangered.
>>>>>
>>>>
>>>> PGPG, huh?
>>>>
>>>> And how would you know that the PGP public key you have is in fact
>>>> the key of the correct real state agency, and not of some other
>>>> "person"? How are you going to ensure the proper chain of trust, hein?
>>>>
>>>> That's assuming that the hackers don't have control of the agency
>>>> computer.
>>>>
>>>>> https://sourceforge.net/projects/gentlegpg/
>>>>>
>>>>>
>>>>> Some other:
>>>>>
>>>>> https://www.gpg4win.org/
>>>>> https://sourceforge.net/projects/ppgp/
>>>>>
>>>>>
>>>
>>>  Key are signed.
>>
>> By whom?
>>
>> You need to walk to the company first, in person, and exchange keys.
>> And then make sure not to download other keys and not to trust the web
>> of trust, because you do not control who signs what.
>>
>> I know quite well PGP, I use it, and it is not going to work for
>> business.
> 
>  So do nothing, PLEASE!  My your fall be great and embittering!

Why would I do nothing? I would not use PGP for business, that's all.

-- 
Cheers,
       Carlos E.R.

[toc] | [prev] | [next] | [standalone]


#50931

FromWouter Verhelst <w@uter.be>
Date2018-09-25 17:17 +0200
Message-ID<750q7f-n4a.ln1@gangtai.home.grep.be>
In reply to#50928
On 9/25/18 4:26 PM, Carlos E. R. wrote:
> Why would I do nothing? I would not use PGP for business, that's all.

I have used it for business. When I send an email to my business partner
that is sensitive, I usually PGP-encrypt it to his key.

But yeah, I agree that it's fairly useless in the general case.

[toc] | [prev] | [next] | [standalone]


#50949

From"Carlos E. R." <robin_listas@es.invalid>
Date2018-09-26 14:16 -0400
Message-ID<g120ohFvegU1@mid.individual.net>
In reply to#50931
On 25/09/2018 11.17, Wouter Verhelst wrote:
> On 9/25/18 4:26 PM, Carlos E. R. wrote:
>> Why would I do nothing? I would not use PGP for business, that's all.
> 
> I have used it for business. When I send an email to my business partner
> that is sensitive, I usually PGP-encrypt it to his key.
> 
> But yeah, I agree that it's fairly useless in the general case.

People with which I needed to use encryption were unable to set any
encryption method up. A lawyer, for instance. I would have to go to his
office and teach him.

With banks it is usually a web form. And the staff is forbidden from
installing anything, anyway, so asking is useless.

-- 
Cheers,
       Carlos E.R.

[toc] | [prev] | [next] | [standalone]


#50950

Fromnospam <nospam@nospam.invalid>
Date2018-09-26 14:24 -0400
Message-ID<260920181424291054%nospam@nospam.invalid>
In reply to#50949
In article <g120ohFvegU1@mid.individual.net>, Carlos E. R.
<robin_listas@es.invalid> wrote:

> 
> People with which I needed to use encryption were unable to set any
> encryption method up. A lawyer, for instance. I would have to go to his
> office and teach him.

use an encrypted email service. there's nothing to set up. all they
need is a browser or an app on their phone.

[toc] | [prev] | [next] | [standalone]


#50951

From"Carlos E. R." <robin_listas@es.invalid>
Date2018-09-26 14:47 -0400
Message-ID<g122hjF19bmU1@mid.individual.net>
In reply to#50950
On 26/09/2018 14.24, nospam wrote:
> In article <g120ohFvegU1@mid.individual.net>, Carlos E. R.
> <robin_listas@es.invalid> wrote:
> 
>>
>> People with which I needed to use encryption were unable to set any
>> encryption method up. A lawyer, for instance. I would have to go to his
>> office and teach him.
> 
> use an encrypted email service. there's nothing to set up. all they
> need is a browser or an app on their phone.

That would require a binding contract and spend money, which they did
not want to do.

-- 
Cheers,
       Carlos E.R.

[toc] | [prev] | [next] | [standalone]


#50952

Fromnospam <nospam@nospam.invalid>
Date2018-09-26 14:56 -0400
Message-ID<260920181456366663%nospam@nospam.invalid>
In reply to#50951
In article <g122hjF19bmU1@mid.individual.net>, Carlos E. R.
<robin_listas@es.invalid> wrote:

> >> People with which I needed to use encryption were unable to set any
> >> encryption method up. A lawyer, for instance. I would have to go to his
> >> office and teach him.
> > 
> > use an encrypted email service. there's nothing to set up. all they
> > need is a browser or an app on their phone.
> 
> That would require a binding contract and spend money, which they did
> not want to do.

no it wouldn't. it only needs a mutual agreement to use an encrypted
medium. there are free options as well as paid ones. choose whichever
one works best for all parties involved.

lawyers should be using such a system anyway because they are required
to keep certain information confidential.

[toc] | [prev] | [next] | [standalone]


#50953

From"Carlos E. R." <robin_listas@es.invalid>
Date2018-09-26 22:20 -0400
Message-ID<g12t2oF6en0U1@mid.individual.net>
In reply to#50952
On 26/09/2018 14.56, nospam wrote:
> In article <g122hjF19bmU1@mid.individual.net>, Carlos E. R.
> <robin_listas@es.invalid> wrote:
> 
>>>> People with which I needed to use encryption were unable to set any
>>>> encryption method up. A lawyer, for instance. I would have to go to his
>>>> office and teach him.
>>>
>>> use an encrypted email service. there's nothing to set up. all they
>>> need is a browser or an app on their phone.
>>
>> That would require a binding contract and spend money, which they did
>> not want to do.
> 
> no it wouldn't. it only needs a mutual agreement to use an encrypted
> medium. there are free options as well as paid ones. choose whichever
> one works best for all parties involved.

Not for a lawyer, it wouldn't. He would be directly liable if the email
gets intercepted or somehow compromised.

> 
> lawyers should be using such a system anyway because they are required
> to keep certain information confidential.

Good old paper and couriers.


-- 
Cheers,
       Carlos E.R.

[toc] | [prev] | [next] | [standalone]


#50957

Fromnospam <nospam@nospam.invalid>
Date2018-09-27 00:43 -0400
Message-ID<270920180043163968%nospam@nospam.invalid>
In reply to#50953
In article <g12t2oF6en0U1@mid.individual.net>, Carlos E. R.
<robin_listas@es.invalid> wrote:

> >>>> People with which I needed to use encryption were unable to set any
> >>>> encryption method up. A lawyer, for instance. I would have to go to his
> >>>> office and teach him.
> >>>
> >>> use an encrypted email service. there's nothing to set up. all they
> >>> need is a browser or an app on their phone.
> >>
> >> That would require a binding contract and spend money, which they did
> >> not want to do.
> > 
> > no it wouldn't. it only needs a mutual agreement to use an encrypted
> > medium. there are free options as well as paid ones. choose whichever
> > one works best for all parties involved.
> 
> Not for a lawyer, it wouldn't. He would be directly liable if the email
> gets intercepted or somehow compromised.

it's actually ideal for a lawyer, since it's basically impossible to
intercept and crack end-to-end encrypted email unless the passcode is
something trivially guessed.

> > lawyers should be using such a system anyway because they are required
> > to keep certain information confidential.
> 
> Good old paper and couriers.

a courier could mysteriously disappear, along with the documents. then
what?

nothing is perfect.

[toc] | [prev] | [next] | [standalone]


#50974

From"Carlos E. R." <robin_listas@es.invalid>
Date2018-09-27 11:21 -0400
Message-ID<g14ar9Ffdg9U1@mid.individual.net>
In reply to#50957
On 27/09/2018 00.43, nospam wrote:
> In article <g12t2oF6en0U1@mid.individual.net>, Carlos E. R.
> <robin_listas@es.invalid> wrote:
> 
>>>>>> People with which I needed to use encryption were unable to set any
>>>>>> encryption method up. A lawyer, for instance. I would have to go to his
>>>>>> office and teach him.
>>>>>
>>>>> use an encrypted email service. there's nothing to set up. all they
>>>>> need is a browser or an app on their phone.
>>>>
>>>> That would require a binding contract and spend money, which they did
>>>> not want to do.
>>>
>>> no it wouldn't. it only needs a mutual agreement to use an encrypted
>>> medium. there are free options as well as paid ones. choose whichever
>>> one works best for all parties involved.
>>
>> Not for a lawyer, it wouldn't. He would be directly liable if the email
>> gets intercepted or somehow compromised.
> 
> it's actually ideal for a lawyer, since it's basically impossible to
> intercept and crack end-to-end encrypted email unless the passcode is
> something trivially guessed.

We know that. He may or may not, but that would be irrelevant. :-)

He needs to pay someone that says "yes, this is safe". With a contract.

> 
>>> lawyers should be using such a system anyway because they are required
>>> to keep certain information confidential.
>>
>> Good old paper and couriers.
> 
> a courier could mysteriously disappear, along with the documents. then
> what?

Sue the courier company :-)

> 
> nothing is perfect.
> 


-- 
Cheers,
       Carlos E.R.

[toc] | [prev] | [next] | [standalone]


Page 1 of 2  [1] 2  Next page →

Back to top | Article view | alt.os.linux


csiph-web