Creating the perfect GPG keypair
31–40 of 40 posts
Re: Creating the perfect GPG keypair
#32And the length of this is exactly the reason why Johnny still can't encrypt and doesn't want to know how. Getting things right, including disaster recovery, should be done correctly and silently by default.
I think for gpg and encrypted communications to take off, it has to come in the form of an easy to use app combined with a service offering, similar to how TextSecure/Signal works. Though it should use GPG and have a variant for Android, iOS, and native desktop clients. The cloud service offering should be email and instant messaging, email, and some levels of sync (but not the private key). It should be/do: - Open s…
Projects like this are why I continue to use Fdroid, Cyanogen AOSP, and believe the open source movement on mobile is worth the hassle. Oh yea, that and Password Store.
Re: Creating the perfect GPG keypair
#33Earlier quoted context omitted.
> And then you drop your key and lose it. Or it gets ran over by a car or something. Now what? You can't have both, I think. With a physical key your only concern is the physical security of the key. One should print out the revocation certificate, though. I don't think many people lose their home keys or get them run over by a car. It's just a matter of making that a priority.
> I don't think many people lose their home keys or get them run over by a car. All it needs is some idiot emptying his drink over your pants to fry an USB device. Or a drunk driver crashing into your bike and breaking the device. Print out your passphrase-protected keyset, put it together with an encrypted copy of your most common passwords (I know no one uses a dedicated password for every site!) and your KeePass/K…
Re: Creating the perfect GPG keypair
#34Earlier quoted context omitted.
> I don't think many people lose their home keys or get them run over by a car. All it needs is some idiot emptying his drink over your pants to fry an USB device. Or a drunk driver crashing into your bike and breaking the device. Print out your passphrase-protected keyset, put it together with an encrypted copy of your most common passwords (I know no one uses a dedicated password for every site!) and your KeePass/K…
Yes, people do use different passwords for each site, and you should, too. :)
Re: Creating the perfect GPG keypair
#35Re: Creating the perfect GPG keypair
#36Here's the (67 Lines of Code) script: http://pastie.org/10631164 It's not really prepared for public release so forgive some ungainly code.
Re: Creating the perfect GPG keypair
#37Re: Creating the perfect GPG keypair
#38Now of course this doesn't mean that subkeys are unnecessary, but the author should probably find a more realistic threat model that readers who are already privacy-conscious can more easily sympathize with.
Re: Creating the perfect GPG keypair
#39Earlier quoted context omitted.
I think for gpg and encrypted communications to take off, it has to come in the form of an easy to use app combined with a service offering, similar to how TextSecure/Signal works. Though it should use GPG and have a variant for Android, iOS, and native desktop clients. The cloud service offering should be email and instant messaging, email, and some levels of sync (but not the private key). It should be/do: - Open s…
I am merely a user, not a contributor yet. But I would say a solid base, and not a full implementation of your wanted features list, is in OpenKeychain. http://www.openkeychain.org/ Projects like this are why I continue to use Fdroid, Cyanogen AOSP, and believe the open source movement on mobile is worth the hassle. Oh yea, that and Password Store. https://github.com/zeapo/Android-Password-Store/
- Dominik
Re: Creating the perfect GPG keypair
#40I can't believe they use an existing domain, shire.org for their example. I'm one of the owners of a domain name that's people use as dummy address when they sign up for stuff. I can't stand getting mail like that. There is a reserved name for examples, it's EXAMPLE.COM.
Every domain except for example.com is an existing domain.
example.com, example.net and example.org for second level domains and the top level domain "invalid."