Live data from Hacker News

The GNU Privacy Handbook (1999)

gnupg.org

11–17 of 17 posts

Re: The GNU Privacy Handbook (1999)

#11
post #10

Earlier quoted context omitted.

There is NitroKey[0], which seemed to me like a good alternative to Yubikey, but I haven't ordered either yet so I can't say I have first-hand experience. But much luck if you decide to go with it, something I'm looking more and more into, especially since I too use password-store and it would be good having an easier to use setup that is still secure. [0] https://www.nitrokey.com/

Nitrokey claims on their homepage that the firmware of the Storage version of NitroKey can be updated by software. This seems to mean that there's someone out there with a key that can sign arbitrary code that can be loaded as an update and gains access to the crypto material on the device.

I had a look through their instructions and I'm not sure if there is a signing process that happens. You have to enable firmware access from the app, and then it's a bog standard DFU flash to load the new firmware.

Re: The GNU Privacy Handbook (1999)

#12
post #5

Wow, this is so old (1999) it's terrible. It recommends generating DSA keys. Interesting as a historic artefact, but please don't follow this guide, search for something more recent.

I'd be curious to read what article is better, so you who search, please share your findings

Re: The GNU Privacy Handbook (1999)

#13
post #12
post #5

Wow, this is so old (1999) it's terrible. It recommends generating DSA keys. Interesting as a historic artefact, but please don't follow this guide, search for something more recent.

I'd be curious to read what article is better, so you who search, please share your findings

For always up to date guides try the CryptoParty Handbook: https://www.cryptoparty.in/learn/handbook

Re: The GNU Privacy Handbook (1999)

#14
post #6

For a much more gentle (and illustrated) introduction do public-key encryption, GnuPG and how to use it with email (Thunderbird + Enigmail), see FSF's Email Self-Defense: https://emailselfdefense.fsf.org/ Tactical Tech's Security in-a-Box has more detailed, step-by-step, multiple platform guides for the same tools: https://securityinabox.org/en/guide/thunderbird/windows https://securityinabox.org/en/guide/thunderbird…

Thank you.

Re: The GNU Privacy Handbook (1999)

#15
post #4

first page: "You must also choose a key size. The size of a DSA key must be between 512 and 1024 bits". Definitely do not follow this guide nowadays :D

Good ol' times. Wonder if one can make a Google query to get old keys, ripe for cracking

Re: The GNU Privacy Handbook (1999)

#17
post #10

Earlier quoted context omitted.

Nitrokey claims on their homepage that the firmware of the Storage version of NitroKey can be updated by software. This seems to mean that there's someone out there with a key that can sign arbitrary code that can be loaded as an update and gains access to the crypto material on the device.

I had a look through their instructions and I'm not sure if there is a signing process that happens. You have to enable firmware access from the app, and then it's a bog standard DFU flash to load the new firmware.

Does it require you to perform any physical actions on the dongle? If not, why can't I straightforwardly extract keys if I own the machine the dongle is attached to?
Post reply on HN