I'm a little worried about generating a new "master" RSA key nowadays, since it seems like ECC is right on the horizon of going mainstream. I would generate a new Ed25519 key today with GPG 2.1, but Curve25519 encryption isn't supported yet (only signing is). Does anyone else have the same feeling of apprehension?
Secure yourself, Part 1: Air-gapped computer, GPG and smartcards
21–30 of 62 posts
Re: Secure yourself, Part 1: Air-gapped computer, GPG and smartcards
#22"quite possible that this kind of device will be the norm in 10 years" I want to believe this, but I just can't see people caring, ever. The worst has already happened. Edward Snowdon has exposed that government can, and does, look at you penis and we still don't care.
Re: Secure yourself, Part 1: Air-gapped computer, GPG and smartcards
#23Earlier quoted context omitted.
I used to run this until I couldn't ignore that it was pointless because it offloads the attack vector to something I can easily lose, have taken or replaced. Or someone could come in an pop in a drive with their own kernel. Nevermind the reality that I'd never completely follow through with the security measures needed on a personal machine. I'd just be giving myself an active role in my home's security theater. I j…
The card also contains certificate protected by password.
Still somewhat vulnerable to a replaced BIOS and/or a hardware key logger (I gather the idea is: I can keep my usb key safe easier than my laptop. I'm not sure if that's true in a meaningful way).
Re: Secure yourself, Part 1: Air-gapped computer, GPG and smartcards
#24"quite possible that this kind of device will be the norm in 10 years" I want to believe this, but I just can't see people caring, ever. The worst has already happened. Edward Snowdon has exposed that government can, and does, look at you penis and we still don't care.
Looking at your penis is hardly the worst that can happen. People will really start to care when the data is used for a violent crackdown of a popular domestic political movement. https://en.wikipedia.org/wiki/Palmer_Raids
Re: Secure yourself, Part 1: Air-gapped computer, GPG and smartcards
#25"quite possible that this kind of device will be the norm in 10 years" I want to believe this, but I just can't see people caring, ever. The worst has already happened. Edward Snowdon has exposed that government can, and does, look at you penis and we still don't care.
Re: Secure yourself, Part 1: Air-gapped computer, GPG and smartcards
#26How easy is it for somebody to get your PGP key off a yubikey if they stole it? In particular since physical devices can be fuzzed, etc, it might be worse than an encrypted keychain on device for some people?
Re: Secure yourself, Part 1: Air-gapped computer, GPG and smartcards
#27This guide doesn't take into account side-channel attacks.[0] [0] http://en.wikipedia.org/wiki/Side-channel_attack
Re: Secure yourself, Part 1: Air-gapped computer, GPG and smartcards
#28Some ideas:
* Disk encryption
* Always-on VPNs, like Cloak
* Encrypting DNS
* 1Password and proper secret management
* Privacy screens (e.g. in coffee shops or on airplanes. Sounds stupid - but surprisingly important.)
* Two-step verification, both in software and hardware (Yubikey)
* Good browser extensions - e.g. https everywhere, ad blocking (for security purposes)
* USB condoms on all phone charger cables
etc.
Re: Secure yourself, Part 1: Air-gapped computer, GPG and smartcards
#29"Many people believe the Holy Grail of secure isolation is to use two or more physically separate machines. This belief seems so natural, that we often don't give it much thought. After all, what better isolation could we possible get than physical "airgap"?
I would like to discuss two exemplary scenarios involving isolation: one for securing the Tor process and another for securing email operations, and compare the pros and cons of using the physical isolation vs. the software compartmentalization as currently possible on Qubes OS."
Re: Secure yourself, Part 1: Air-gapped computer, GPG and smartcards
#30"quite possible that this kind of device will be the norm in 10 years" I want to believe this, but I just can't see people caring, ever. The worst has already happened. Edward Snowdon has exposed that government can, and does, look at you penis and we still don't care.