funsec mailing list archives

Re: Inmate E-Mail (someone guessed right)


From: "Justin Scott" <admin () dtdns com>
Date: Wed, 1 Dec 2010 14:49:03 -0500

Nice to see this option for incarcerated people and their
families, though at 50 cents per email it's a bit costly imho.

Frankly, I'm inclined to agree and have mentioned that on several occasions
to the powers that be.  They're fairly confident that it's the right price
point though.

1.  I've noticed a the lack of SSL on the credit ordering
page where credit card info is entered [1]

How embarrassing, I will ensure our lead developer (me) is flogged for
forgetting to flip the "require ssl" bit on the live settings.  That has
been corrected, and thank you for pointing it out.

2.  The TOS section here is a bit confusing, especially the
term "public area" -- am I to understand that all user content/

I'll pass the note along to legal.

3.  I expect there's likely some very interesting intelligence
that could be gathered from these communications, both from a
LEA and more academic nature.  Will be interesting to see how
this plays out.

I suspect over time there will be.  The jail has the ability to search or
read the messages as needed.  They can enter keywords or phrases that can
flag or quarantine messages for review, but it's up to them how it's used.


-Justin


_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: