From owner-freebsd-chat@FreeBSD.ORG Thu Jul 12 19:36:50 2007 Return-Path: X-Original-To: chat@freebsd.org Delivered-To: freebsd-chat@FreeBSD.ORG Received: from mx1.freebsd.org (mx1.freebsd.org [69.147.83.52]) by hub.freebsd.org (Postfix) with ESMTP id 4B54516A468 for ; Thu, 12 Jul 2007 19:36:50 +0000 (UTC) (envelope-from davids@webmaster.com) Received: from mail1.webmaster.com (mail1.webmaster.com [216.152.64.169]) by mx1.freebsd.org (Postfix) with ESMTP id 329A913C448 for ; Thu, 12 Jul 2007 19:36:50 +0000 (UTC) (envelope-from davids@webmaster.com) Received: from however by webmaster.com (MDaemon.PRO.v8.1.3.R) with ESMTP id md50001586984.msg for ; Thu, 12 Jul 2007 12:36:26 -0700 From: "David Schwartz" To: "Jim Capozzoli" , =?utf-8?Q?Dag-Erling_=22Sm=C3=B8rgrav=22?= Date: Thu, 12 Jul 2007 12:35:57 -0700 Message-ID: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Priority: 3 (Normal) X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook IMO, Build 9.0.6604 (9.0.2911.0) In-Reply-To: <86wsx5h487.fsf@dwp.des.no> Importance: Normal X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3138 X-Authenticated-Sender: joelkatz@webmaster.com X-Spam-Processed: mail1.webmaster.com, Thu, 12 Jul 2007 12:36:26 -0700 (not processed: message from trusted or authenticated source) X-MDRemoteIP: 206.171.168.138 X-Return-Path: davids@webmaster.com X-MDaemon-Deliver-To: chat@freebsd.org X-MDAV-Processed: mail1.webmaster.com, Thu, 12 Jul 2007 12:36:28 -0700 Cc: chat@freebsd.org Subject: RE: ADVERT: C12G X-BeenThere: freebsd-chat@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list Reply-To: davids@webmaster.com List-Id: Non technical items related to the community List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 12 Jul 2007 19:36:50 -0000 > I would strongly advise against using any cryptographic product based = on > an algorithm which was designed by an amateur and has never been = subject > to review or cryptanalysis. >=20 > DES There are what appear to me on quick inspection to be serious flaws in = the this software. For example, it uses RSA without proper padding. The = website says "E-mail is encrypted using the RSA public-key cryptosystem = thus eliminating security risks from symmetric ciphers." Any security = expert will tell you that this raises immediate red flags. (And = inspection of the code strongly suggests that it's as bad as it sounds.) DS