5 ms·
It's standard practice to encrypt your emails when sending potential security notifications to the party that you're notifying. Not only does it keep out prying
by leftnode 14y ago
It's standard practice to encrypt your emails when sending potential security notifications to the party that you're notifying. Not only does it keep out prying eyes, it ensures the person sending the email is who they say they are.
- bigiain 14y ago"it ensures the person sending the email is who they say they are" Although, if you're going to trust the pgp key you get sent when you mail someone asking for one, you don't have any more assurance that you're encrypting it to the person you intended, and you _almost_ may as well have sent it in cleartext in the initial email... Get your pgp fingerprints in some out-of-band method of communication. (When was the last time anybody even heard of a key signing party? I attended on at the Perl Conference in '98 or '99 - don't think I've been aware of one happening in any of my circles since)
- Titanous 14y agoIn this case I was able to confirm the key by matching it with a copy they uploaded to https://policy.heroku.com/security https://policy.heroku.com/security
- bigiain 14y agoGood to hear. Now the paranoid in me is wondering - if there's an attacker deeply entrenched enough to be reading their plain-text email, either on the wire between them and you or with sufficient root privs on their infrastructure, they could probably have arranged their own pgp key to appear there for you as well. If I were trying to ensure I was doing my utmost best diligence, I'd have tried to include a completely non-internet backchannel - perhaps a call phone number for Heroku sourced from a dead-tree phone book (if such a thing exists anymore?) and get someone to read out the key fingerprint.
- ktizo 14y agoAccept nothing less than the full company board singing the entire key to you in binary at a restaurant of your choosing.
- bigiain 14y agoHeh… I'd like to hope the whole "web of trust" idea could solve this problem. If I've got a large enough set of people I've been sending signed or encrypted email too using a particular key, that history means I've got a pretty reliable idea that the key is "real". With a bit of luck, if enough of my set of people has their own group of historically-verified keys, I might have a good enough chance of finding someone I know and trust who'll vouch for a key fingerprint of someone I need to securely communicate with. (I wonder if pgp signing registration email or payment receipts might help here? Or perhaps including key fingerprints? It'd be nice to be able to mail a user/customer saying "here's our PGP key, and you can check it against the key fingerprint we sent you when you signed up" or maybe " … that we print on every invoice" ?)
- ktizo 14y agoPerhaps people who rely on a longstanding online reputation could provide a service as verifiable online keystores for many different organisations via their own public key, so providing a distributed and multiply redundant public key resource that would be incredibly difficult to hack all in one go to fake a specific key.
- rdl 14y agoWidely communicating your key fingerprint makes sense. I put it on my business cards, etc. Back in the late 1990s people were talking about publishing root key fingerprints in newspapers, engraving them on stone tablets, etc. I.e. things which obviously required a lot of money be expended, thus making casual forgery less likely.
- rdl 14y agoWidely communicating your key fingerprint makes sense. I put it on my business cards, etc. Back in the late 1990s people were talking about publishing root key fingerprints in newspapers, engraving them on stone tablets, etc. I.e. things which obviously required a lot of money be expended, thus making casual forgery less likely.
- lightcatcher 14y agoDoes it warm your heart that key signing parties still happen about twice each year at Caltech?
- willvarfar 14y agoah yes, key signing parties http://xkcd.com/364/ http://xkcd.com/364/ :)