A Server-oriented Incognito?

Pat Double pat at patdouble.com
Thu Oct 18 14:53:36 UTC 2007


On Thursday 18 October 2007, Marco Bonetti wrote:
> > Is that a problem for security or anonymity?
>
> both, I think: if a malicious user can exploit the extension he surely can
> break your anonimity

True. I wonder what the risks there are, running any executable? Triggering 
something bad in gpg, but I think that would happen regardless of how well 
FireGPG calls gpg.

> > Incognito is not using Windows
>
> ok, THAT was clear :D
> I pointed it out as a side note to highlight FireGPG still early
> development stage

Yeah, I waited for quite a while before even looking at it. I did not see a 
release yet so I took a closer look and it seemed OK. I am putting a specific 
version from SVN so nothing gets put in unexpected.

-- 
Pat Double, pat at patdouble.com
"Ye must be born again." - John 3:7
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: This is a digitally signed message part.
URL: <http://lists.torproject.org/pipermail/tor-talk/attachments/20071018/ac173a0f/attachment.pgp>


More information about the tor-talk mailing list