From mark at kingant.net  Mon Apr  1 03:50:57 2013
From: mark at kingant.net (Mark Doliner)
Date: Mon, 1 Apr 2013 00:50:57 -0700
Subject: Force https for imfreedom.org website?
Message-ID: <CAPZ8mV6wMQ-R7jP0pjVVODtYO70GOJMBUNS_Q_1YRLv0R8fizA@mail.gmail.com>

How do people feel about redirecting from http to https for all URLs on
imfreedom.org?

My reasons for wanting to do this are:
- Secure interactions with the protocol documentation wiki to prevent
password stealing and session hijacking.
- Reduce the chances of a MITM sending altered content to a user.  This is
extremely unlikely, because who in their right mind would want to mess with
this content...?  I mean, who cares?

Downsides:
- We'll have to keep buying SSL certs.
- Little bit slower to load, especially for users with high latency to our
server, (TLS negotiation requires  more round trips).
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://pidgin.im/pipermail/discussion/attachments/20130401/6e791a9f/attachment.html>

From kstange at pidgin.im  Mon Apr  1 18:40:08 2013
From: kstange at pidgin.im (Kevin Stange)
Date: Mon, 01 Apr 2013 17:40:08 -0500
Subject: Force https for imfreedom.org website?
In-Reply-To: <CAPZ8mV6wMQ-R7jP0pjVVODtYO70GOJMBUNS_Q_1YRLv0R8fizA@mail.gmail.com>
References: <CAPZ8mV6wMQ-R7jP0pjVVODtYO70GOJMBUNS_Q_1YRLv0R8fizA@mail.gmail.com>
Message-ID: <515A0CC8.5080909@pidgin.im>

On 04/01/2013 02:50 AM, Mark Doliner wrote:
> How do people feel about redirecting from http to https for all URLs on
> imfreedom.org <http://imfreedom.org>?
>
> My reasons for wanting to do this are:
> - Secure interactions with the protocol documentation wiki to prevent
> password stealing and session hijacking.
> - Reduce the chances of a MITM sending altered content to a user. ? This
> is extremely unlikely, because who in their right mind would want to
> mess with this content...? ? I mean, who cares?

This sounds fine.  I'm in favor of having all pidgin resources that we 
want verifiable on SSL as long as we have the CPU power.  A lot of deal 
has been made about serving our downloads from SSL.  I am fine with this 
and Steadfast is on board if we want to serve downloads from the server 
(nicobar) to accomplish this.

> Downsides:
> - We'll have to keep buying SSL certs.

We can continue to get SSL certificates startcom for free as long as we 
don't need EV certs or wildcards.  We can get pretty much as many as we 
want.  The only concern is that normally each cert requires a separate 
IP unless we want to assume all the browsers we see support passing the 
SSL vhost information.

> - Little bit slower to load, especially for users with high latency to
> our server, (TLS negotiation requires ? more round trips).

I am not concerned about this.

Kevin


From mark at kingant.net  Sun Apr 14 17:48:57 2013
From: mark at kingant.net (Mark Doliner)
Date: Sun, 14 Apr 2013 14:48:57 -0700
Subject: Meeting soon?
In-Reply-To: <CAPZ8mV6FM94BqjDRg0d1_=EsW-UGs4y=O_QWocmBTA3T_c8E=g@mail.gmail.com>
References: <514538FA.5020705@pidgin.im>
	<DD09C2E3FF334CA8949D8EA4CFF2B2FB@gmail.com>
	<762173DE-7C22-4C26-95AD-0026DCBC2B9B@pidgin.im>
	<C3259E35CEDE4E16ADD0B5DE5EE263E4@gmail.com>
	<CAPZ8mV49gMm=AXhGtAdSDxaaK-bgKZ_K-KMx=mJAXFJ8gg3gFw@mail.gmail.com>
	<20130318033523.GA18176@mail.kb8ojh.net>
	<388187DDA0C247BB998EE6282A33F1F4@gmail.com>
	<CAPZ8mV5P+HsUPgxgLffbfNKWpxr4FEKKhdyv37nmYeDWtsg_hA@mail.gmail.com>
	<CAPirPssEswQEfVDHZM0jXrvOrrjUnSOx3-p4PGoj+P_FE76D_g@mail.gmail.com>
	<CAPZ8mV6FM94BqjDRg0d1_=EsW-UGs4y=O_QWocmBTA3T_c8E=g@mail.gmail.com>
Message-ID: <CAPZ8mV7kGmjnJzpxoXq4Z79Bu-5-tMKsyHjNiCzae1ZJaVmAKA@mail.gmail.com>

Just a reminder that the board meeting is 24.75 hours from now.
Specifically, Monday April 14 at
22:30 GMT/UTC
18:30 EDT
15:30 PDT

I looked into Google Hangouts and I don't think it's a good solution.
I think it will be easier for us to dial into a conference call
number.  I found a random free service called Rondee that's pretty
easy to use and provides recordings.  How about we try that?  Is
everyone ok with dialing a non-tollfree US number?

Dial: (409) 777-9000 or (916) 209-4534
PIN: 8398876



Anyone is welcome to call in (including non-board members), but please
don't speak during the meeting if you're not on the board.  I imagine
some of us will be hanging out in devel at conference.pidgin.im and
boardroom at conference.pidgin.im on XMPP during the meeting, if you have
questions or things to share.

If anyone is curious, here's the story with Google Handouts:
Normal Google Hangouts allow the initiator to invite Google users who
have a computer with microphone and speakers/headphones, and it allows
the initiator to dial phone numbers and have them join the meeting.
It's mildly inconvenient for the initiator to have to invite and dial
people, and it's not possible to record the call.

"Google Hangouts On Air" is similar to the above.  Differences are
that it automatically records a video and posts it on YouTube, which
is convenient, but unfortunately it does not allow dialog telephones,
and I'm guessing that will be inconvenient for some people.

_______________________________________________
Board mailing list
Board at imfreedom.org
http://pidgin.im/cgi-bin/mailman/listinfo/board


From mark at kingant.net  Mon Apr 15 18:00:29 2013
From: mark at kingant.net (Mark Doliner)
Date: Mon, 15 Apr 2013 15:00:29 -0700
Subject: Meeting soon?
In-Reply-To: <CAPZ8mV7kGmjnJzpxoXq4Z79Bu-5-tMKsyHjNiCzae1ZJaVmAKA@mail.gmail.com>
References: <514538FA.5020705@pidgin.im>
	<DD09C2E3FF334CA8949D8EA4CFF2B2FB@gmail.com>
	<762173DE-7C22-4C26-95AD-0026DCBC2B9B@pidgin.im>
	<C3259E35CEDE4E16ADD0B5DE5EE263E4@gmail.com>
	<CAPZ8mV49gMm=AXhGtAdSDxaaK-bgKZ_K-KMx=mJAXFJ8gg3gFw@mail.gmail.com>
	<20130318033523.GA18176@mail.kb8ojh.net>
	<388187DDA0C247BB998EE6282A33F1F4@gmail.com>
	<CAPZ8mV5P+HsUPgxgLffbfNKWpxr4FEKKhdyv37nmYeDWtsg_hA@mail.gmail.com>
	<CAPirPssEswQEfVDHZM0jXrvOrrjUnSOx3-p4PGoj+P_FE76D_g@mail.gmail.com>
	<CAPZ8mV6FM94BqjDRg0d1_=EsW-UGs4y=O_QWocmBTA3T_c8E=g@mail.gmail.com>
	<CAPZ8mV7kGmjnJzpxoXq4Z79Bu-5-tMKsyHjNiCzae1ZJaVmAKA@mail.gmail.com>
Message-ID: <CAPZ8mV6wY8sQjW6mPThHRJNY3TS5cwZoSSQrdNag01P-gpFDnw@mail.gmail.com>

30 minute reminder!

On Sun, Apr 14, 2013 at 2:48 PM, Mark Doliner <mark at kingant.net> wrote:
> Dial: (409) 777-9000 or (916) 209-4534
> PIN: 8398876

_______________________________________________
Board mailing list
Board at imfreedom.org
http://pidgin.im/cgi-bin/mailman/listinfo/board


From lschiere at pidgin.im  Mon Apr 15 18:51:16 2013
From: lschiere at pidgin.im (Luke Schierer)
Date: Mon, 15 Apr 2013 18:51:16 -0400
Subject: Meeting Minutes from 2013-04-15 meeting
Message-ID: <4C277D4A-D8D0-48B5-B81C-7CB6CDCC1199@pidgin.im>

Meeting started at 18:30 EDT on April 15Th 2013.

Called to order at 18:36.

Mark Doliner: Present
Ethan Blanton: Present
Luke Schierer: Present
John Bailey: Present
Sean Egan: Absent
Mark Spencer: Absent
Even Schoenberg: Absent - arrived during treasurer's report.

Minutes from the previous meeting posted at http://imfreedom.org/minutes-20120418.php

Motion to approve the minutes as posted was unanimously approved.

Treasurer's Report:
        Books closed for 2012.
        Started the year with 20830.86
        took in 2706.59
                86.10  from Adium and credited to them. 
                607.97 from affiliate account
                12.38 interest
                2000.00 from summer of code
                -14.27 from fees for affiliate payment
        Ended year with 23523.18

        Opened a pay-pal account with no activity.

        2013 to date (as of 2013/04/09)
        Opened year with 23523.18
                219.18 Affiliate Payments
                10505.00 from donations
                        5.00 from Mark Doliner
                        The rest from Google UK
                -342.32 in fees so far.

Treasurer's Report Approved unanimously.

Motion to re-nominate all board members to current positions was unanimously passed.
Reelection was passed unanimously.

Ethan notified the board that he had not yet paid him self the authorized reimbursement for registering IMF with the state of Delaware.

Ethan motioned to pre-approve the renewal fee with Delaware. This was 170.00 last year.
This motion was passed unanimously.

Meeting adjourned at 18:49.

_______________________________________________
Board mailing list
Board at imfreedom.org
http://pidgin.im/cgi-bin/mailman/listinfo/board


From elb at pidgin.im  Mon Apr 15 19:19:21 2013
From: elb at pidgin.im (Ethan Blanton)
Date: Mon, 15 Apr 2013 19:19:21 -0400
Subject: Meeting Minutes from 2013-04-15 meeting
In-Reply-To: <4C277D4A-D8D0-48B5-B81C-7CB6CDCC1199@pidgin.im>
References: <4C277D4A-D8D0-48B5-B81C-7CB6CDCC1199@pidgin.im>
Message-ID: <20130415231921.GA10137@mail.kb8ojh.net>

Luke Schierer spake unto us the following wisdom:
>         Opened a pay-pal account with no activity.

Clarification: there was activity on the paypal account (the affiliate
payments and associated fees), just nothing of note.  The important
point was that we opened an additional financial account during the
year.  Sorry for any confusion.

Thanks,
Ethan
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 482 bytes
Desc: Digital signature
URL: <http://pidgin.im/pipermail/discussion/attachments/20130415/0dde1404/attachment.pgp>
-------------- next part --------------
_______________________________________________
Board mailing list
Board at imfreedom.org
http://pidgin.im/cgi-bin/mailman/listinfo/board

