ietf-openpgp
[Top] [All Lists]

Re: Czech attack to PGP - keep the kimono closed

2001-03-22 13:25:39
At 7:49 PM +0000 3/22/01, Lutz Donnerhacke wrote:
Ack. We should stress that private key files should not reside on shared
media and that OpenPGP ist a transport message format, not a local storage
recommendation. Implementations are free to choose anything else.

Yes, definitely, Lutz. This has been mentioned in a number of different messages, but this is probably the single most important point, and worth singling it out. Transferring secret key files makes them vulnerable to attack. Vlastimil and Rosa have shown a particular way to attack them.

best,

--

john noerenberg
jwn2(_at_)qualcomm(_dot_)com
  --------------------------------------------------------------------------
  Peace of mind isn't at all superficial, really.  It's the whole thing.
  That which produces it is good maintenance; that which disturbs it
  is poor maintenance.
  -- Zen and the Art of Motorcycle Maintenance, Robert M. Pirsig, 1974
  --------------------------------------------------------------------------

<Prev in Thread] Current Thread [Next in Thread>