[Assword] [PATCH] use ENCRYPT_NO_COMPRESS if available

Daniel Kahn Gillmor dkg at fifthhorseman.net
Tue May 20 14:48:30 EDT 2014


On 05/09/2014 02:20 PM, Jameson Graef Rollins wrote:
> On Thu, May 08 2014, Daniel Kahn Gillmor <dkg at fifthhorseman.net> wrote:

>> Upcoming versions of gpgme should support a GPGME_ENCRYPT_NO_COMPRESS
>> option.  python-gpgme should add support for it once gpgme exposes the
>> flag.  The use of this flag should invalidate any CRIME-style attacks.

Just for the record:

I've submitted https://bugs.launchpad.net/pygpgme/+bug/1321412 to
encourage PyGPGME to adopt the flag as well.  so when all three packages
are upgraded, assword will be able to encrypt without compression.

	--dkg

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 1010 bytes
Desc: OpenPGP digital signature
URL: <https://lists.mayfirst.org/mailman/private/assword/attachments/20140520/f383e2dc/attachment.pgp>


More information about the Assword mailing list