home | list info | list archive | date index | thread index

Re: Secure messaging?


At this point, several people have commented on the open nature of this group, its membership, the meetings (when they were in person), and its archives. To the best of my recollection, that was a design choice and we even had some mild contention on my not publishing the online meeting key until just before the meeting and not making it a simple pattern as being a little on the "not open enough" side.

We have had GPG/PGP themed meetings and key signings in the past, so that is still a possibility for anyone who wants secured/verified messaging. As that is a web of trust concept, you will still only be securing messaging between people who you already know in some manner and trust at some minimal level when you sigh their key. It was even a thing we had set up for the end of our in-person meetings.

Based on a quick search (not in depth), you can get GPG/PGP integrated to pretty much any platform you want, including popular smart phones, so having secured email communications with some subset of the people on the list is not difficult as long as all participants have each others keys. Keys are typically published to one of the key servers, so obtaining established keys is not difficult either. People do choose to not publish keys, so you may need to obtain the keys directly.

There are rules for GPG/PGP key signing parties, however these rules are set up for a group of unknown people to meet in person to sign each other's keys in a manner that provides some level of third party trust (assuming you trust government organizations to issue properly verified credentials) through recognized issuers.

We do not have a secure messaging hub for members, nor do I think we want to get into that business given the voluntary/hobby nature of the group. Once you start something like that, you are now talking all manner of safety/security guidelines, privacy expectations, etc. I think that is a lot of effort and responsibility for this group. I'm not even sure what toolkit we would use for such a thing, as it never crossed my mind that we would do something like that - barring some possible group exercise to try something like it out for education purposes.

Just my $0.05 (since we no longer have one cent coins).

--
Scott Murphy

message navigation