[ numbers ]

Gastown Security


All content © 1996 Gastown Webspace Updated:

Web form to PGP e-mail Gateway

[ web to PGP network diagram ]

Frequently Asked Questions

  1. How does the Web To PGP service work?

    Your customers can use an SSL-supporting browser such as Netscape to submit form data (such as credit card numbers or confidential requests) which is then encrypted using ViaCrypt PGP 2.7 and e-mailed to you.

  2. What are some security vulnerabilities with this service?

    The parties which you need to trust are:

  3. What version of PGP should I use?

    If you in the U.S. or Canada, you are expected to purchase a license for Viacrypt PGP if you are using PGP for non-personal purposes. In other countries, use an international version of PGP, but expected to pay a license fee for the use of the IDEA technology in PGP if you are using it for commercial (money-making) purposes. This is not a legal opinion, it is only the information that The Mayor has been made aware of from various sources.

How to establish your Web To PGP gateway

  1. Install PGP on your computer and generate your public key.

    For general information about PGP and its implementations, visit the PGP site in Norway.
  2. E-mail your PGP public key to The Mayor

    The public key you send will be used to encrypt messages which will be e-mailed to the person who pays the fees for the service. An alternate e-mail address cannot be used, and your public key will not be certified by Gastown Webspace. Messages will not be signed by Gastown Webspace, and you should not rely on the date/time stamp of the e-mail.
  3. Create your web form and e-mail message template.

    The easiest way to get started is to view source on The Mayor's secure feedback form and message template files. Remember that the message template file must contain UNIX carriage returns (not DOS or MAC linefeeds) and you need to add a header line which is used to identify your public key, such as:

    X-Secure: accountname
    
    
  4. Test your form before linking to it from your pages.

    Please do not link your page until you have tested it yourself using a web browser which supports SSL connections. When you create your link, use an absolute reference to your URL which specifies the https:// (SSL) connection protocol. If you use a relative link to the page, people will be typing their data into a form which does not appear secure (i.e. no blue line, key icon broken) even though the SSL connection will be used when they hit the submit button. Also be sure that you are familiar with the process of decrypting the PGP messages which you receive.
  5. Mail your payment to Gastown Webspace.

    Current tenants of Gastown can use this service at no extra charge during their current term of service if they mail their 6-month web space renewal fee plus $20 for 6 months of Web To PGP service. For information about Gastown tenant services and prices, see how to move into Gastown.

DISCLAIMER

GASTOWN WEBSPACE ASSUMES NO LIABILITY FOR THE CONSEQUENCES OF ANY SECURITY WEAKNESS WHICH ALLOWS CONFIDENTIAL INFORMATION TO BE OBTAINED BY UNINTENDED RECIPIENTS. USERS OF THE WEB TO PGP SERVICE WAIVE ALL CLAIMS TO DAMAGES EVEN IF THEY RESULT FROM NEGLIGENCE BY GASTOWN WEBSPACE OR ITS DESIGNATED AGENTS. USE OF THE SERVICE CONSITUTES ACCEPTANCE OF THESE TERMS.

Cypherpunks beware

Gastown Webspace's private key is not stored on a server on the Internet at all, since the Web to PGP service does not need it; outgoing e-mail messages are not digitally signed. The Gastown account on XMission is maintained using an SSH secure telnet connection, so don't bother looking for the password with a packet filter. Go away and be nice to somebody.


Back to Gastown
If you have questions or comments about Gastown, send personal e-mail to:
The Mayor <mayor@gastown.com>


Gastown Webspace is not an editor or a publisher, and therefore claims no responsibility for the content of materials stored in this directory heirarchy.