Live data from Hacker News

Secure yourself, Part 1: Air-gapped computer, GPG and smartcards

viccuad.me

21–30 of 62 posts

Re: Secure yourself, Part 1: Air-gapped computer, GPG and smartcards

#21

I'm a little worried about generating a new "master" RSA key nowadays, since it seems like ECC is right on the horizon of going mainstream. I would generate a new Ed25519 key today with GPG 2.1, but Curve25519 encryption isn't supported yet (only signing is). Does anyone else have the same feeling of apprehension?

There's no reason you can't transition from a master RSA key to a master DSA key?

Re: Secure yourself, Part 1: Air-gapped computer, GPG and smartcards

#22
post #17

"quite possible that this kind of device will be the norm in 10 years" I want to believe this, but I just can't see people caring, ever. The worst has already happened. Edward Snowdon has exposed that government can, and does, look at you penis and we still don't care.

Looking at your penis is hardly the worst that can happen. People will really start to care when the data is used for a violent crackdown of a popular domestic political movement.

https://en.wikipedia.org/wiki/Palmer_Raids

Re: Secure yourself, Part 1: Air-gapped computer, GPG and smartcards

#23
post #19

Earlier quoted context omitted.

I used to run this until I couldn't ignore that it was pointless because it offloads the attack vector to something I can easily lose, have taken or replaced. Or someone could come in an pop in a drive with their own kernel. Nevermind the reality that I'd never completely follow through with the security measures needed on a personal machine. I'd just be giving myself an active role in my home's security theater. I j…

The card also contains certificate protected by password.

Your initial comment was a bit brief; Now I realize you meant "just use full disk encryption/luks with the bootloader and boot-partion on a removable device -- to lessen the chances that the password prompt has been modified to capture your password (back-door bootloader, backdoor kernel/initrd)".

Still somewhat vulnerable to a replaced BIOS and/or a hardware key logger (I gather the idea is: I can keep my usb key safe easier than my laptop. I'm not sure if that's true in a meaningful way).

Re: Secure yourself, Part 1: Air-gapped computer, GPG and smartcards

#24
post #17

"quite possible that this kind of device will be the norm in 10 years" I want to believe this, but I just can't see people caring, ever. The worst has already happened. Edward Snowdon has exposed that government can, and does, look at you penis and we still don't care.

Looking at your penis is hardly the worst that can happen. People will really start to care when the data is used for a violent crackdown of a popular domestic political movement. https://en.wikipedia.org/wiki/Palmer_Raids

Well we are coming up on the hundred year anniversary of that so it could happen. I try to get my grandma to use encryption but she won't.

Re: Secure yourself, Part 1: Air-gapped computer, GPG and smartcards

#26
post #3

How easy is it for somebody to get your PGP key off a yubikey if they stole it? In particular since physical devices can be fuzzed, etc, it might be worse than an encrypted keychain on device for some people?

After three pin attempts, the key is wiped.

Re: Secure yourself, Part 1: Air-gapped computer, GPG and smartcards

#28
I would enjoy a "pragmatic security" article about how individuals could adopt enterprise-standard security without too much technical knowledge or additional hardware. This could target freelancers or travelers, but I think that there are a lot of engineers who want to secure their personal laptop in a manner similar to their company laptop.

Some ideas:

* Disk encryption

* Always-on VPNs, like Cloak

* Encrypting DNS

* 1Password and proper secret management

* Privacy screens (e.g. in coffee shops or on airplanes. Sounds stupid - but surprisingly important.)

* Two-step verification, both in software and hardware (Yubikey)

* Good browser extensions - e.g. https everywhere, ad blocking (for security purposes)

* USB condoms on all phone charger cables

etc.

Re: Secure yourself, Part 1: Air-gapped computer, GPG and smartcards

#29
Here's a 2014 paper from Qubes, http://www.invisiblethingslab.com/resources/2014/Software_co...

"Many people believe the Holy Grail of secure isolation is to use two or more physically separate machines. This belief seems so natural, that we often don't give it much thought. After all, what better isolation could we possible get than physical "airgap"?

I would like to discuss two exemplary scenarios involving isolation: one for securing the Tor process and another for securing email operations, and compare the pros and cons of using the physical isolation vs. the software compartmentalization as currently possible on Qubes OS."

Re: Secure yourself, Part 1: Air-gapped computer, GPG and smartcards

#30
post #17

"quite possible that this kind of device will be the norm in 10 years" I want to believe this, but I just can't see people caring, ever. The worst has already happened. Edward Snowdon has exposed that government can, and does, look at you penis and we still don't care.

Why would you even care if this was standard or not. People value their privacy differently.
Post reply on HN