[imp] Issues with PGP support in IMP

Michael M Slusarz slusarz@bigworm.colorado.edu
Thu, 9 May 2002 18:37:18 -0600


Quoting Iain <iain@minihub.org>:
| From what I can see the implementation of PGP support in IMP stores
| private 
| keys on a server. Now, every piece of documentation I have ever read on
| PGP 
| says that this is a bad idea and is not how PGP should be used.
| 
| Is there support for using private keys stored on a floppy or some other
| removable media? It would seem to me that doing this properly becomes 
| extremely non trivial as it would mean a Java applet with the encryption
| algorithms built in. Something along the lines of hushmail - although I
| think 
| that still stores the keys in a central database.

Yup - this is definitely an issue.  My goal is to make this clear to the 
user; this was something i was going to implement once the implementation 
has been tested for awhile.

BTW, there was discussion on this topic in the following thread:
http://marc.theaimsgroup.com/?l=horde-dev&m=101721186209238&w=2
Look at my comments, and others replies, to statement #5.

michael

______________________________________________
Michael Slusarz [slusarz@bigworm.colorado.edu]
The University of Colorado at Boulder