[45059] in Cypherpunks
Warning about Pegasus Mail and PGP (fwd)
daemon@ATHENA.MIT.EDU (anonymous-remailer@shell.portal.co)
Sat Dec 9 16:14:01 1995
Date: Sat, 9 Dec 1995 13:08:53 -0800
To: cypherpunks@toad.com
From: anonymous-remailer@shell.portal.com
Forwarded message.
From: investor@flood.xnet.com (Investortools)
Newsgroups: alt.security.pgp
Subject: warning about PMail-PGP
Date: 9 Dec 1995 00:47:46 GMT
Organization: XNet - A Full Service Internet Provider - (708) 983-6064
Lines: 5
Message-ID: <4aambi$e33@flood.xnet.com>
NNTP-Posting-Host: cyclone.xnet.com
X-Newsreader: TIN [version 1.2 PL2]
I just installed the "Open Encryptor" PGP interface for Pegasus Mail. I found that when you sign a message and queue it, it stores your password in the clear on the hard drive. Apparently
it doesn't sign or encrypt the message until just before
transmitting it. So it stores your PGP private key password
with the message until it sends it.