X-Git-Url: https://git.cworth.org/git?a=blobdiff_plain;f=meetings%2Fhd2015.mdwn;h=add26ca530ec526242755a490d59b97a9bad8d71;hb=42bf578717c5ac63b818876555929bcc842c8523;hp=fb8cb53c2965a189026b3db03bf944471b03fdf6;hpb=a0e1699f08db6052e88dfb6aee72ca2127d68a18;p=notmuch-wiki diff --git a/meetings/hd2015.mdwn b/meetings/hd2015.mdwn index fb8cb53..add26ca 100644 --- a/meetings/hd2015.mdwn +++ b/meetings/hd2015.mdwn @@ -20,25 +20,29 @@ Moving parts for secure e-mail * GnuPG (C) * Emacs UI (emacs lisp) * notmuch-emacs - * mml-mode + * mml-mode, mm multimedia rendering library * Alot / nmbug / nmbug-status (python) * python-bindings * webmail: * noservice (Clojure) * notmuch web (Haskell) -Security concerns ------------------ +Security and privacy concerns +----------------------------- * privacy leaks rendering messages -* wrong key selection during composition -* reply (message mode defaults) -* inline PGP * message-id collisions +* Oops I just sent... + * wrong key selection during composition + * reply (message mode defaults) +* inline PGP + * webmail authentication/authorization (multiple users?) * webmail message escaping (XSS, etc) * shell injection * terminal escape sequences * S/MIME support + * signatures + * encryption * reproducible builds: [sphinx man pages](https://reproducible.debian.net/rb-pkg/testing/amd64/notmuch.html) @@ -61,12 +65,6 @@ Reportbacks ------------------------- -proposed session: ---------- - * Improving the security of the Emacs MML mime composer - * Searching of GPG encrypted mail - * Auditing and fixing "webbug" style problems in front ends ---------- more complete agenda: