From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.org!not-for-mail From: ken manheimer Newsgroups: gmane.emacs.devel Subject: Re: Suggestion for epa-mail-mode Date: Mon, 20 Dec 2010 17:52:16 -0500 Message-ID: References: <20100726.062715.451057314.wl@gnu.org> NNTP-Posting-Host: lo.gmane.org Mime-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-1 X-Trace: dough.gmane.org 1292885565 4601 80.91.229.12 (20 Dec 2010 22:52:45 GMT) X-Complaints-To: usenet@dough.gmane.org NNTP-Posting-Date: Mon, 20 Dec 2010 22:52:45 +0000 (UTC) Cc: Daiki Ueno , rms@gnu.org, emacs-devel@gnu.org To: Leo Original-X-From: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Mon Dec 20 23:52:40 2010 Return-path: Envelope-to: ged-emacs-devel@m.gmane.org Original-Received: from lists.gnu.org ([199.232.76.165]) by lo.gmane.org with esmtp (Exim 4.69) (envelope-from ) id 1PUoau-0006wV-Ka for ged-emacs-devel@m.gmane.org; Mon, 20 Dec 2010 23:52:40 +0100 Original-Received: from localhost ([127.0.0.1]:42396 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.43) id 1PUoau-00084J-28 for ged-emacs-devel@m.gmane.org; Mon, 20 Dec 2010 17:52:40 -0500 Original-Received: from [140.186.70.92] (port=57896 helo=eggs.gnu.org) by lists.gnu.org with esmtp (Exim 4.43) id 1PUoap-000817-Bx for emacs-devel@gnu.org; Mon, 20 Dec 2010 17:52:36 -0500 Original-Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1PUoao-0001oz-8R for emacs-devel@gnu.org; Mon, 20 Dec 2010 17:52:35 -0500 Original-Received: from mail-ww0-f49.google.com ([74.125.82.49]:38341) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1PUoao-0001ol-28; Mon, 20 Dec 2010 17:52:34 -0500 Original-Received: by wwb17 with SMTP id 17so3451504wwb.30 for ; Mon, 20 Dec 2010 14:52:32 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:received:mime-version:received:in-reply-to :references:from:date:message-id:subject:to:cc:content-type; bh=pdUP16IdvOOJBSvwgJZzx3bp5+L/0pmme1S3cn7/iyA=; b=SQvHyLRDuqHIt+bBf/NbOLmSEhSmKsCi1ZIZU8ycQClk9rmop5Mfbx8axkw3xwhwO3 lH7KtFLzTqU3WZotd2XsCivKd7p60GFjLJqaYeToID6LrbvYEq9zJyl/AzCaitjUJpBE QH9yChSs3wy2m1h1FSrbyySwzEssaA0I5yLps= DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc:content-type; b=Iv1o9+A56Jje9svhQTkdgQUCVWQiGkDK7w6lUBuHjnaaQ21SHCDOJvKXdg8A8Ylrm4 SHo+vlpAwCDCrPzlYq7hq8O0NEr6jCt59jlwUJ3z+WG9pkZyMcFAaJZIjVvM4bH3Zsrg iIiQE9GRPREjY8L+b62Tek6xuKpBPhHcwzXIY= Original-Received: by 10.216.87.131 with SMTP id y3mr8892618wee.3.1292885552113; Mon, 20 Dec 2010 14:52:32 -0800 (PST) Original-Received: by 10.216.65.141 with HTTP; Mon, 20 Dec 2010 14:52:16 -0800 (PST) In-Reply-To: X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.6 (newer, 2) X-BeenThere: emacs-devel@gnu.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Emacs development discussions." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Original-Sender: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Errors-To: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Xref: news.gmane.org gmane.emacs.devel:133854 Archived-At: On Mon, Dec 20, 2010 at 5:22 PM, Leo wrote: > > Hello Ken, > > On 2010-07-26 16:12 +0100, ken manheimer wrote: > > I'LL be working on it all in a few weeks, with priority on the pgg -> > > epg migration. > > Thank you for fixing allout.el for epg ;) thanks, leo. i'm genuinely sorry it took so long. in fact, there were some substantial features i had to trade-off in the transition. allout is more cumbersome and error-prone for dealing with symmetric encodings for numerous encrypted entries in a file, because i had to let go of encryption passphrase validation and hinting. that comes in exchange for significantly less insecurity due to no handling of passphrases in emacs code. instead, as always when using epg with GnuPG version 2, all passphrase handling is outside of emacs, in gnupg's gpg, gpg-agent, and pinentry, which i expect are drastically less vulnerable. it is for that reason that i was ultimately willing to forego those features, though i wish i could have more control without greater vulnerability... ken > Kind regards, > Leo