GPG keys and removable media
Karsten M. Self
kmself at ix.netcom.com
Sat Nov 23 01:22:52 PST 2002
on Thu, Nov 14, 2002, ME (dugan at passwall.com) wrote:
> minnigerode said:
> > On Thu, 2002-11-14 at 09:54, mkjanes at sonic.net wrote:
> >>
> >> Just a quick (in more ways than one) thought on keyrings and
> >> removable media. At first I was advised to keep my GPG keys,
> >> especially my private key, on a floppy disk. They have adequate
> >> room, but I found it slowed GPG down a lot vs. having the keys on
> >> the hard drive.
This suggestion generally has _more_ to do with having a backup copy of
your keys then of how you should use them. Though if you're security
minded, floppied probably ain't bad.
The suggestion also predates many alternatives to floppy media.
> > You can also keep it on one of those USB ram disks.
<...>
> In using ZIP/Floppy/USB keyring with MB of storage, there is still the
> re-statement of what I included at the meeting: "Like ssh, gpg is for
> *trusted* machines."
Depends on your threat model. If it's casual snooping, using _a_ GPG
key is more useful than sending everything in the clear. If you're
working in supersecret mode, yes, you should take additional precautions
-- trusted hardware, hardened room, air-gap, etc.
But for most of us, use of _some_ crypto is more useful than none at
all. What's important is to be aware of the possible risks.
Peace.
--
Karsten M. Self <kmself at ix.netcom.com> http://kmself.home.netcom.com/
What Part of "Gestalt" don't you understand?
On why IBM wins: "IBM has been able to play the vendors off each
other. Sun and Microsoft hate each other, while Sun and Microsoft
only hate IBM some of the time."
-- James Governor http://news.com.com/2100-1001-912906.html?tag=fd_lede
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: not available
Url : http://nblug.org/pipermail/talk/attachments/20021123/9b85d85e/attachment.pgp
More information about the talk
mailing list