"quite possible that this kind of device will be the norm in 10 years" I want to believe this, but I just can't see people caring, ever. The worst has already happened. Edward Snowdon has exposed that government can, and does, look at you penis and we still don't care.
Secure yourself, Part 1: Air-gapped computer, GPG and smartcards
41–50 of 62 posts
Re: Secure yourself, Part 1: Air-gapped computer, GPG and smartcards
#42I've read so many different multi-factor authentication schemes, and they're often brilliant, but I've yet to come across one that would pass the "my grandpa could use it" usability test. The holy grail for security, to me, will be something (an OS with it elegantly integrated for example) that the user has to try hard not to use, but doesn't feel like they're having an O'Reilly encryption book rammed down their gull…
Re: Secure yourself, Part 1: Air-gapped computer, GPG and smartcards
#43Fix please?
Re: Secure yourself, Part 1: Air-gapped computer, GPG and smartcards
#44Earlier quoted context omitted.
I don't know how difficult it would be to obtain the key from the device. However, if you have a strong passphrase on the key itself, then even if an attacker obtained the key, there would not be a lot to worry about. Just revoke it and move on. They'll likely never guess the passphrase.
The passphrase you set on a GPG private key only applies to keys stored on-disk in the keychain or exported from the keychain. Once you import one into a Yubikey or other OpenPGPCard device, there is no passphrase anymore, you're relying on the card itself to protect it against side-channel attacks, prevent unauthorized or insecure export of the key (Yubikeys don't allow this at all though), and authorize the use of…
Re: Secure yourself, Part 1: Air-gapped computer, GPG and smartcards
#45Earlier quoted context omitted.
For a little while, I used a YubiKey NEO-n as an OpenPGP smartcard, with gpg-agent running as an ssh-agent (so that my SSH key was only present on my smartcard). While great in theory, the authentication time made it totally impractical to connect to multiple servers at once. I know this doesn't invalidate the general idea of using gpg-agent as ssh-agent -- just an anecdote.
Can you elaborate on 'authentication time made it totally impractical' ? Does this mean it was slow? I'm using gpg-agent on osx with a neo-n to ssh into boxes and it's not noticeably slow.
This is a somewhat unusual use-case, I will grant, but I also found a somewhat-noticeable delay in connecting to a single server, on the order of several hundred milliseconds.
I wonder if it would all be fine with a 2k key.
Re: Secure yourself, Part 1: Air-gapped computer, GPG and smartcards
#46The airgapped computer loads propriety Chinese blobs to boot and is pulling it's encryption software over the network via HTTP.
Re: Secure yourself, Part 1: Air-gapped computer, GPG and smartcards
#47Re: Secure yourself, Part 1: Air-gapped computer, GPG and smartcards
#48The airgapped computer loads propriety Chinese blobs to boot and is pulling it's encryption software over the network via HTTP.
I mean that's a level of paranoia I usually don't hold to, but if you are going to go all out, I have to wonder if there is a more secure form of non volatile memory.
Re: Secure yourself, Part 1: Air-gapped computer, GPG and smartcards
#49Earlier quoted context omitted.
Can you elaborate on 'authentication time made it totally impractical' ? Does this mean it was slow? I'm using gpg-agent on osx with a neo-n to ssh into boxes and it's not noticeably slow.
I got this just this second on my debian8 system. :~$ time ssh an6n@mybox exit real 0m1.910s user 0m0.024s sys 0m0.000s
Re: Secure yourself, Part 1: Air-gapped computer, GPG and smartcards
#50"quite possible that this kind of device will be the norm in 10 years" I want to believe this, but I just can't see people caring, ever. The worst has already happened. Edward Snowdon has exposed that government can, and does, look at you penis and we still don't care.
Looking at your penis is hardly the worst that can happen. People will really start to care when the data is used for a violent crackdown of a popular domestic political movement. https://en.wikipedia.org/wiki/Palmer_Raids
What is it about technology where people think the failure was information, not the bunch of dudes cracking you in the head with rifle butts, the legislators who approved the action and the public which votes them into office (including all the people who say they're so outraged with everything they'll just refuse to vote or engage with the political process - because yeah, that's sure showing them).