<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Gumption Blog &#187; security</title>
	<atom:link href="http://www.gumption.com/blog/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gumption.com/blog</link>
	<description>Resisting Gumption Traps Since 1995</description>
	<lastBuildDate>Thu, 23 Jul 2009 21:45:24 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Being Sneaky</title>
		<link>http://www.gumption.com/blog/2007/06/05/being-sneaky/</link>
		<comments>http://www.gumption.com/blog/2007/06/05/being-sneaky/#comments</comments>
		<pubDate>Tue, 05 Jun 2007 18:49:09 +0000</pubDate>
		<dc:creator>thomas</dc:creator>
				<category><![CDATA[gumption]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.gumption.com/blog/2007/06/05/being-sneaky/</guid>
		<description><![CDATA[So, I read out about FireGPG (and, thus, gnupg as well) on slashdot today. FireGPG is a firefox plugin that adds gnupg signing/encryption right into gmail. It&#8217;s pretty slick and I highly recommend it. Remember, without encryption, your e-mails are like postcards in the real mail. That is, anyone along the way to its destination [...]]]></description>
			<content:encoded><![CDATA[<p>So, I read out about <a href="http://firegpg.tuxfamily.org/">FireGPG</a> (and, thus, <a href="http://www.gnupg.org/">gnupg</a> as well) on <a href="http://www.slashdot.org/">slashdot</a> today.  FireGPG is a firefox plugin that adds gnupg signing/encryption right into gmail.  It&#8217;s pretty slick and I highly recommend it.</p>
<p>Remember, without encryption, your e-mails are like postcards in the real mail.  That is, anyone along the way to its destination can easily read it.  Encrypting your e-mail text with gnupg is like putting your postcard in an envelope.  It&#8217;s not totally secure (<a href="http://www.plex86.org/linux/GnuPG..-have-you-ever-wondered-2156.html">especially from the NSA</a>), but it makes it much harder for strangers to read your dirty little secrets.</p>
<p>So, in the interest of carrying on future e-mail conversations in private (when appropriate), here is the public key for my main e-mail address (thomas, you know, at gumption.com):</p>
<p><code><br />
-----BEGIN PGP PUBLIC KEY BLOCK-----<br />
Version: GnuPG v1.4.6 (Darwin)<br />
mQGiBEZlpbsRBAC+OhEyLtvvXhtkququ9Xxk0A8pnwWQoEif3UyFoggncnKcDVZX<br />
or7JdrJBo1eNsOK6o5lTCZjqub/soqwI+6HF+oBq75/KPwW4a7u1kP6agmes7cbR<br />
MZe3/0eQGckpHQrV5EfD15/EeuXtQjUjqm+G39T431edfbQ+0BFUOeVLKwCgrlEN<br />
d0YvJkKjptTqBUngL1E9rc8D/0hmYOE725z5Fvm0dd3+FSUBfsKjxbyH3gT8XQZ/<br />
he44bHe9MbYks6L25I8FcwO+nTSyw2Ytv+WGL1zNqyXfdCDtpP2YEm+YnEx6PaEI<br />
Vp9X+PlhLsxjJeaMfYOsBfpeUxhAJjkYRPwKteWGeYnUjFSKIhu0GbIPPgyR7kes<br />
DNnQA/9sKfEHVi0eQbLjtQaXxyEsH2GwRaGGGwSXStTQEyC1Z3eLBUrNulIFYvwC<br />
dcJwnVhY99WOmCStpsO9Np+4K857hgVVNHz3+FKwZXHF/aPGv1Sftqr6iUrY/7op<br />
K434jXzgVmNJCDanaid8Kp8PnBFY8w2aX6RT8hx2FCTYHARpCLQqVGhvbWFzIEJv<br />
aG1iYWNoLCBKci4gPHRob21hc0BndW1wdGlvbi5jb20+iGAEExECACAFAkZlpbsC<br />
GwMGCwkIBwMCBBUCCAMEFgIDAQIeAQIXgAAKCRBXPLnfG4DfjtZwAJ0TKGRwnQ3W<br />
jGBQ2ILM0ZRN7T1vUQCfaMex2trBD8Qtmy8Tfte/lXh+fsa5Ag0ERmWlwRAIAKPA<br />
foOBV2tW3RMFyo6NQGGlZBs6GD1ib2i2cI84meoEYiCpRKc4+y0fTZ+PcW/sMyZP<br />
eIluBZq7YmUD1v8qBNa3M/ldQnlWM1Tfe6WopAfwcUJ/Nmd9L6lQlf6tPpymoELR<br />
48xqco0RwPR3bynZGvUuAaQLMljzvSo9qN/vow2bWFQ1bnOdHY8mVkD5UdXGh36r<br />
wwcJ3aHmIri+AqFpeKMMf01ggDSpJepfNIeTJc6sIGCoQwJIQO9NyyD3/jNSKbdW<br />
GVaZsP1rWqCMisYSWOELPmjM5bS2iGV+7TmEUxwIyJmBqMVy8HCLBqN0YieokANf<br />
o053SQCC5cqhhKA7orMAAwUH/RHj4H9ZlZQ6v1cbVGoEtTNDvtnZj1qa3QWQ5eur<br />
0kdF/yAhLbZ/HREkKEaCKfdTF/ZJCSy0ZtUsoNvQtP/XhzL318UxsMKYOJy9GEaI<br />
TVqHda/VcMrelELfWtsvkK5uvrQFpo/UkBg9J0YQVvwVJd03e2flXiVHNLRUEplL<br />
BziUeeETuyRbw6MsDKUf22uRg28+vwOdUxgaZ7vqoRS/DoTCZ+hSMJTOeCZKM7R0<br />
S0I6Ja6oIwPPVGHca+Rbxv51NYP4Qy20BX9gxms4SbQHMUoUa31+NVIkcsApE+bo<br />
h3zWbbpPpyInY6gcnzHLBnWtgK9gEk6ruigHLj6oFRrJoOGISQQYEQIACQUCRmWl<br />
wQIbDAAKCRBXPLnfG4DfjjgYAJ9GJo/apT5wwxLAK+EVq7xvuWzTZwCdGK0uoKo4<br />
wiTlHXQP5/CTNioGrJk=<br />
=XXAk<br />
-----END PGP PUBLIC KEY BLOCK-----<br />
</code></p>
<p>Of course, you shouldn&#8217;t actually <a href="http://webber.dewinter.com/gnupg_howto/english/GPGMiniHowto-3.html#ss3.6">sign</a> (i.e. blindly trust) this public key as being mine.  Someone could have hacked this post and changed the above key to their public key.  That&#8217;s why you should always verify a public key through <a href="http://webber.dewinter.com/gnupg_howto/english/GPGMiniHowto-1.html#ss1.3">more secure means</a>.  Like calling the owner and having them read their public key fingerprint (a much shorter representation of the public key intended for humans) to you so you can verify that it matches the key you have.  Then you can sign the public key which means that you have verified that the key is correct and actually belongs to who you think it belongs to.</p>
<p>So, now I&#8217;ll just wait patiently for someone to send me some ciphertext.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.gumption.com/blog/2007/06/05/being-sneaky/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
