Delivery-Date: Thu, 21 May 2015 19:47:00 -0400
Return-Path: <tor-talk-bounces@lists.torproject.org>
X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on moria.seul.org
X-Spam-Level: 
X-Spam-Status: No, score=-4.2 required=5.0 tests=BAYES_00,RCVD_IN_DNSWL_MED,
	T_RP_MATCHES_RCVD autolearn=ham version=3.3.1
X-Original-To: archiver@seul.org
Delivered-To: archiver@seul.org
Received: from eugeni.torproject.org (eugeni.torproject.org [38.229.72.13])
	(using TLSv1.2 with cipher ADH-AES256-GCM-SHA384 (256/256 bits))
	(No client certificate requested)
	by khazad-dum.seul.org (Postfix) with ESMTPS id A7E7B1E10A4
	for <archiver@seul.org>; Thu, 21 May 2015 19:46:58 -0400 (EDT)
Received: from eugeni.torproject.org (localhost [127.0.0.1])
	by eugeni.torproject.org (Postfix) with ESMTP id F146135CC9;
	Thu, 21 May 2015 23:46:54 +0000 (UTC)
Received: from localhost (localhost [127.0.0.1])
 by eugeni.torproject.org (Postfix) with ESMTP id D594135CC7
 for <tor-talk@lists.torproject.org>; Thu, 21 May 2015 23:46:50 +0000 (UTC)
X-Virus-Scanned: Debian amavisd-new at 
Received: from eugeni.torproject.org ([127.0.0.1])
 by localhost (eugeni.torproject.org [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id KZcg4Vc8Dd7f for <tor-talk@lists.torproject.org>;
 Thu, 21 May 2015 23:46:50 +0000 (UTC)
Received: from eternauta.sindominio.net (eternauta.sindominio.net
 [80.81.122.47])
 (using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits))
 (Client CN "sindominio.net", Issuer "CAcert Class 3 Root" (not verified))
 by eugeni.torproject.org (Postfix) with ESMTPS id 72E6E35CC6
 for <tor-talk@lists.torproject.org>; Thu, 21 May 2015 23:46:50 +0000 (UTC)
Received: from localhost (localhost.localdomain [127.0.0.1])
 by lesnaus.sindominio.net (Postfix) with ESMTP id A4E6640714A;
 Fri, 22 May 2015 00:52:04 +0200 (CEST)
Received: from eternauta.sindominio.net ([127.0.0.1])
 by localhost (lesnaus.sindominio.net [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id zjBRBtnVw8tS; Fri, 22 May 2015 00:52:01 +0200 (CEST)
Received: from localhost (unknown [5.79.86.129])
 (using TLSv1 with cipher ECDHE-RSA-AES128-SHA (128/128 bits))
 (No client certificate requested)
 by lesnaus.sindominio.net (Postfix) with ESMTPSA id 8E642407131;
 Fri, 22 May 2015 00:52:00 +0200 (CEST)
MIME-Version: 1.0
From: Ruben Pollan <meskio@sindominio.net>
To: tor-talk@lists.torproject.org, Yuri <yuri@rawbw.com>
References: <CAD2Ti2-qdymrnM-nHqP2sVBYP=notY6sW54dQ1to-KTbkTEY4A@mail.gmail.com>
 <555E2BFC.6000709@rawbw.com>
In-Reply-To: <555E2BFC.6000709@rawbw.com>
Message-ID: <20150521224759.10603.72916@KingMob>
Date: Fri, 22 May 2015 00:47:59 +0200
Subject: Re: [tor-talk] Mailpile SMTorP [ref: nexgen P2P email]
X-BeenThere: tor-talk@lists.torproject.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: tor-talk@lists.torproject.org
List-Id: "all discussion about theory, design,
 and development of Onion Routing" <tor-talk.lists.torproject.org>
List-Unsubscribe: <https://lists.torproject.org/cgi-bin/mailman/options/tor-talk>, 
 <mailto:tor-talk-request@lists.torproject.org?subject=unsubscribe>
List-Archive: <http://lists.torproject.org/pipermail/tor-talk/>
List-Post: <mailto:tor-talk@lists.torproject.org>
List-Help: <mailto:tor-talk-request@lists.torproject.org?subject=help>
List-Subscribe: <https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk>, 
 <mailto:tor-talk-request@lists.torproject.org?subject=subscribe>
Content-Type: multipart/mixed; boundary="===============1232128836339243797=="
Errors-To: tor-talk-bounces@lists.torproject.org
Sender: "tor-talk" <tor-talk-bounces@lists.torproject.org>

--===============1232128836339243797==
Content-Type: multipart/signed; protocol="application/pgp-signature";
 micalg="pgp-sha512"; boundary="===============0810239819216718018=="
Content-Disposition: inline

--===============0810239819216718018==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable

Quoting Yuri (2015-05-21 21:03:24)
> On 05/21/2015 00:41, grarpamp wrote:
> > This eliminates the fact that all these new centralised OpenPGP
> > webmail providers will have access to your keys/cleartext, because
> > either:
> > A) it resides there
> > B) the malware they give you to run in your browser gives it away.
> =

> On one hand, Mailpile is after security, which is great. But on the =

> other hand they use node which doesn't sign packages, therefore being =

> vulnerable to MITM attacks. I think, node js is either fundamentally =

> opposed to signing, or wants to bundle it with their commercial version, =

> or something like that. With this trade-off (convenience of node vs =

> security), Mailpile certainly doesn't look like as secure as such system =

> could be.
> =

> Node js also has the insecure command that downloads code direct from =

> github. So if some github project gets hijacked or bought out, guess =

> what will happen?

I find really funny when people rant about things without even looking on w=
hat =

they are talking about.

Mailpile does not use node, it's written in python and all the javascript o=
f it =

is for the browser. Up to now mailpile is in a beta status and is too soon =
to =

value if their distribution methods are trustworthy.

-- =

Ruben Pollan  | http://meskio.net/
-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=
=3D-=3D-=3D-=3D-=3D-
 My contact info: http://meskio.net/crypto.txt
-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=
=3D-=3D-=3D-=3D-=3D-
Nos vamos a Croatan.

--===============0810239819216718018==
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Description: signature
Content-Type: application/pgp-signature; name="signature.asc"; charset="us-ascii"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAABCgAGBQJVXmCfAAoJEMcysdHCj04vIvkP/0ccBV9JP2+eipOMTb8740va
WVKGwOe6E72UP9O+0hde8MJuO6LuXCV3jvUkr8D+OO1Fkl1h6NGKe/WGHjOtTWpG
6SxAX7HvIFgtynAP8jaVRBr4EdZu5wlWHWxuTHSGjFwPDELtJUg/vpRbVVEJOGxI
uyDQgEjL26r/JO90SsMmnJZV6tSXg50NcNhsVl1ud8r3A9YRJuZ4T3d8yhjkrD0o
ky6/bY2EBpKzmjQ/LsC5A61P723BKUVgLS3I+NkUEbJCP56fEAUiwzEdwFXIgB9w
mCtnXTyW09n/Ce5YVZPxZ/T9UwiB+WnvbtCUA482UUy9bdObwqOneAGujJWBmvxg
Pdr5fcwCBxQ5Hu2esQzRyA0wtIYTlSu5hOwBt+6qhmgKPUQSjbW/xYAmZ4JYQi2Y
EJcSPBRprxF9Iv6MbTZBNRMSrFRjLuHkS79qxfSQTay16OrBn3k+1ZG58TeZAmW9
zfiQpGkbCHcvbxxh4zcbIdjgSPIGe5vygkN5jNxDwQW39zt/EPodjRQRikJQ5Xq8
S1kDX5aHhmcPiV+qZC66xQxOJN0QiH0C8DFvZoeceuPQlhfdc17s4T0j/Iy1atst
aiAsYOvoSFht1le82S+5xt/h1/Q/KYXJUuzds7xN/laVqe01aHgHF0TANmBKRn2s
K4pitZp6tah3jp/+TKWf
=amRR
-----END PGP SIGNATURE-----

--===============0810239819216718018==--

--===============1232128836339243797==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

-- 
tor-talk mailing list - tor-talk@lists.torproject.org
To unsubscribe or change other settings go to
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk

--===============1232128836339243797==--

