Live data from Hacker News

Show HN: Vanity GPG Keys (and help fund GnuPG!)

vanitykeys.io

1–10 of 54 posts

Re: Show HN: Vanity GPG Keys (and help fund GnuPG!)

#4
post #3

Hi, I'm getting the following error using Opera 12.17. Unable to complete secure transaction Secure connection: fatal error (40) from server.

That's a slightly old version of Opera. If I could install it now I would test, but hard to find it on package managers.

Re: Show HN: Vanity GPG Keys (and help fund GnuPG!)

#5
post #4
post #3

Hi, I'm getting the following error using Opera 12.17. Unable to complete secure transaction Secure connection: fatal error (40) from server.

That's a slightly old version of Opera. If I could install it now I would test, but hard to find it on package managers.

See here: http://www.opera.com/download/guide/?custom=yes

Re: Show HN: Vanity GPG Keys (and help fund GnuPG!)

#6
post #5
post #4

Earlier quoted context omitted.

That's a slightly old version of Opera. If I could install it now I would test, but hard to find it on package managers.

See here: http://www.opera.com/download/guide/?custom=yes

Version 12.17 isn't there. Any idea why?

Re: Show HN: Vanity GPG Keys (and help fund GnuPG!)

#7
post #6
post #5

Earlier quoted context omitted.

See here: http://www.opera.com/download/guide/?custom=yes

Version 12.17 isn't there. Any idea why?

12.17 was just a security update (Heartbleed), and Linux/Mac were not affected, so 12.16 is the same for them.

Re: Show HN: Vanity GPG Keys (and help fund GnuPG!)

#9
Sorry but no. This makes your private key compromised by default...

The most important rule of public key encryption is... Never (really!) let anybody else handle your private key...

And why should I trust some random website for not storing an extra copy? The keys are definitely not "... as secure as if you have generated them by yourself. ". Because, if I generate them, I know that my box is the only one that had ever touched it...

Re: Show HN: Vanity GPG Keys (and help fund GnuPG!)

#10
post #8

I think it's a very bad idea to use this service. Your secret key should never be shared with a 3rd party. Using an untrusted 3rd party service to generate a public/private key pair is like asking a thief to sell you a new door lock.

I agree, this service should never be used for any serious real-life usage. But this is a _vanity_ key service, and there are legitimate uses for such keys where no harm can be done.

I'm mainly interested in raising awareness to GnuPG and get more people using it - I also organize CryptoParties [1] in my area, exactly for this purpose.

[1] - https://cryptoparty.in/

Post reply on HN