GPG keys and removable media

Karsten M. Self kmself at ix.netcom.com
Sat Nov 23 01:22:52 PST 2002


on Thu, Nov 14, 2002, ME (dugan at passwall.com) wrote:
> minnigerode said:
> > On Thu, 2002-11-14 at 09:54, mkjanes at sonic.net wrote:
> >>
> >> Just a quick (in more ways than one) thought on keyrings and
> >> removable media. At first I was advised to keep my GPG keys,
> >> especially my private key, on a floppy disk. They have adequate
> >> room, but I found it slowed GPG down a lot vs. having the keys on
> >> the hard drive. 

This suggestion generally has _more_ to do with having a backup copy of
your keys then of how you should use them.  Though if you're security
minded, floppied probably ain't bad.

The suggestion also predates many alternatives to floppy media.

> > You can also keep it on one of those USB ram disks.  

<...>

> In using ZIP/Floppy/USB keyring with MB of storage, there is still the
> re-statement of what I included at the meeting: "Like ssh, gpg is for
> *trusted* machines."

Depends on your threat model.  If it's casual snooping, using _a_ GPG
key is more useful than sending everything in the clear.  If you're
working in supersecret mode, yes, you should take additional precautions
-- trusted hardware, hardened room, air-gap, etc.

But for most of us, use of _some_ crypto is more useful than none at
all.  What's important is to be aware of the possible risks.

Peace.

-- 
Karsten M. Self <kmself at ix.netcom.com>        http://kmself.home.netcom.com/
 What Part of "Gestalt" don't you understand?
    On why IBM wins:  "IBM has been able to play the vendors off each
    other.  Sun and Microsoft hate each other, while Sun and Microsoft
    only hate IBM some of the time."
     -- James Governor http://news.com.com/2100-1001-912906.html?tag=fd_lede
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: not available
Url : http://nblug.org/pipermail/talk/attachments/20021123/9b85d85e/attachment.pgp


More information about the talk mailing list