<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<atom:link xmlns:atom="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="https://tanguy.ortolo.eu/blog/feed/rss/commentaires/" />
	<link>https://tanguy.ortolo.eu/blog/article108/webpg</link>
	<language>en</language>
	<description>a blog about Debian and self-hosting</description>
	<lastBuildDate>Wed, 11 Dec 2013 23:21:00 +0000</lastBuildDate>
	<generator>PluXml</generator>
	<item>
		<title>WebPG, a PGP addon for web browsers - Written by Tom Dial @ wednesday 11 december 2013, 23:21</title> 
		<link>https://tanguy.ortolo.eu/blog/article108/webpg/#c1386804095-1</link>
		<guid>https://tanguy.ortolo.eu/blog/article108/webpg/#c1386804095-1</guid>
		<description>While encryption and web browsers surely are a bad mix, the attacks mentioned on Lunar&amp;#039;s reference appear to operate only during message composition and possibly decryption, and point to flaws in FireGPG implementation that may not be present in WebPG.  In addition, they do not expose the plain text more (at worst) than not encrypting at all.  More importantly, they do not appear to address any issues with the encrypted output which will be stored in gmail (for example).

The transient risk of capture during encryption or decryption probably is much smaller than the risk that unencrypted mail will be captured either during composition, transfer, storage on a providers servers, or while being read by a recipient.</description>
		<pubDate>Wed, 11 Dec 2013 23:21:00 +0000</pubDate>
		<dc:creator>Tom Dial</dc:creator>
	</item>
	<item>
		<title>WebPG, a PGP addon for web browsers - Written by Lunar @ saturday 07 september 2013, 16:42</title> 
		<link>https://tanguy.ortolo.eu/blog/article108/webpg/#c1378572172-1</link>
		<guid>https://tanguy.ortolo.eu/blog/article108/webpg/#c1378572172-1</guid>
		<description>FireGPG was discontinued because its other was eventually convinced that it was a very bad idea. There is no way to trust a website to not look at the cleartext before encryption/after decryption if that piece of information is accessible through the DOM.

I strongly suggest you read Tails advisory before advertising it further:
https://tails.boum.org/doc/encryption_and_privacy/FireGPG_susceptible_to_devastating_attacks/</description>
		<pubDate>Sat, 07 Sep 2013 16:42:00 +0000</pubDate>
		<dc:creator>Lunar</dc:creator>
	</item>
		<title>Tanguy Ortolo - WebPG, a PGP addon for web browsers - Comments</title> 
</channel>
</rss>