Re: Is there a chance smartcards have a backdoor? (was Re: Any future for the Crypto Stick?)

2013-12-08 Thread Paul R. Ramer
Peter Lebbing pe...@digitalbrains.com wrote: On 05/12/13 13:20, Paul R. Ramer wrote: On that note, why assume that the manufacturer would not do the opposite: feign helping the spy agency by giving them a compromised ROM and then substituting a secure one on the real product. In either case, we

Re: Holiday giving (crowd-funding campaign?)

2013-12-08 Thread Werner Koch
On Sat, 7 Dec 2013 07:31, pho...@panopticism.net said: Details were scarce, however. This sounds like perfect timing; perhaps either Sam or Werner can provide us with an update on the campaign? Sam is preparing the campaign and twittering on https://twitter.com/gnupg . This campaign will be

Re: Any future for the Crypto Stick?

2013-12-08 Thread Werner Koch
On Sat, 7 Dec 2013 11:29, ein...@pvv.org said: AFAIK, the US has no import restrictions on cryptography, and the RSA patent ran out years ago, so e.g. shop.kernelconcepts.de should be able to ship it to you. IIRC, Petra of kernelconcepts told me that there is no problem for them to ship to

Re: Is there a chance smartcards have a backdoor? (was Re: Any future for the Crypto Stick?)

2013-12-08 Thread NdK
Il 08/12/2013 14:15, Mark Schneider ha scritto: A little security is not real security. There always can be backdoors in the firmware (BIOS, closed source drivers etc). Why is everyone thinking 'BIOS' as backdoorable piece of sw? Why not the hard disk? http://spritesmods.com/?art=hddhack Just

Re: Is there a chance smartcards have a backdoor? (was Re: Any future for the Crypto Stick?)

2013-12-08 Thread Mark Schneider
Am 08.12.2013 19:13, schrieb NdK: Why is everyone thinking 'BIOS' as backdoorable piece of sw? Why not the hard disk? http://spritesmods.com/?art=hddhack Just another piece to think of when building a secure system... Excellent article! Thank you. Writing firmware I meant every piece of code

Re: Is there a chance smartcards have a backdoor? (was Re: Any future for the Crypto Stick?)

2013-12-08 Thread Peter Lebbing
On 08/12/13 21:13, Mark Schneider wrote: BTW: there is no video at: http://achtbaan.nikhef.nl/events/OHM/video/d2-t1-13-20130801-2300-hard_disks_more_than_just_block_devices-sprite_tm.m4v You can find it at:

determine the source(s) of validity

2013-12-08 Thread Hauke Laging
Hello, I want to find out what makes a key valid (and with which certification level): a certification by one of the systems keys or one or more certifications from the WoT. I think that it is important that applications show this information in key selection dialogs. IIRC this has been

Re: Holiday giving

2013-12-08 Thread Hauke Laging
Am Fr 06.12.2013, 23:16:57 schrieb Robert J. Hansen: And to encourage you to make your own contribution, And to make that easier I add the URL: http://www.g10code.de/gnupg-donation.html Furthermore I would like to encourage everyone to spread the mailinglist archive link to Rob's mail