[Mailman-Developers] Mailman and GPG.

Omri Schwarz ocschwar@MIT.EDU
Mon, 06 Nov 2000 14:54:38 -0500


> On Sun, Nov 05, 2000 at 05:55:37PM -0500, The guy named after an Om Kalthoum song wrote:
> 
> [ Mailman using GPG to decrypt and re-crypt messages ]
> 
> > I may be itnerested in doing this as an exercise to learn
> > Python. Has anyone done something like this? 
> 
> I don't think so. It's the first I heard about it, in any case. Note that
> "it isn't that simple" ;) You have to think about Archives. Do you want to
> enable them over SSL only ? SSL with client certificates ? Do you just want
> to disable them ? What about news gatewaying ? Just disable it for 'secure'
> groups, or just sign the postings ?

The motivation I have behind asking 
(which can quickly drift off-topic for this list)
is that the main reason behind the failure of
widespread email encryption is human factors.
Therefore, the right amount of social engineering 
will be the driving force in getting people to encrypt email.

If a mailing list exploder like what I described is available,
people will learn not to 1. share TMI type information
on any other kind of mailing list, or 2. share proprietary
discussions on any other kind of mailing list.

So, a list like this will 
1. have no Web archiving,
2. no news gatewaying, and
3. rapidly expiring mailing list keypairs, Just In Case (TM).

I'm asking this on the Mailman forum because
Mailman would be easier to GPG-enable than
Majordomo (just as eating ice cream is more pleasant
than root canal..), and because apart from that, I am
not picky on how this should be done, hence 
would be willing to fork Mailman to warp it for this end.

-- 
-------
Omri Schwarz ocschwar@mit.edu 
"Fair enough: anyone who believes that the laws of physics are | "Prof drop!"
mere social conventions is invited to try transgressing        | "Thud."
those conventions from the windows of my apartment.            | "Ow!
(I live on the twenty-first floor.)" Alan Sokal - Physicist    |  My Spleen!"