Re: Question about the security of the GnuPG Agent with regard to cryptographic material scrubbing

2019-02-26 Thread Ciprian Dorin Craciun
On Tue, Feb 26, 2019 at 12:58 PM Sarun Intaralawan wrote: > I'm not able to answer your main question, but I believe it is you explained. > However, regarding the matter in P.S., I'm glad to inform you that such a > tool exists. It is called pass [1] and it is fully integrated with GnuPG and >

Question about the security of the GnuPG Agent with regard to cryptographic material scrubbing

2019-02-26 Thread Ciprian Dorin Craciun
Hello all! Given the recent survey in password managers security [1], which concluded with their failure to properly sanitize / scrub the sensitive data (i.e. "master key") in "running locked state", I was wondering how does GnuPG Agent fare in this regard? More specifically: * let's assume that

Re: Encrypt USB-HDD with LUKS using OpenPGP smartcard?

2018-08-15 Thread Ciprian Dorin Craciun
On Wed, Aug 15, 2018 at 1:57 PM Peter Lebbing wrote: > > https://gist.github.com/cipriancraciun/c8a0dfb973b586053c167fec91093d9c > > Hey, that systemd service file seems to basically grab cryptsetup > handling from the clutches of systemd, enabling all sorts of operations > not possible with

Re: Encrypt USB-HDD with LUKS using OpenPGP smartcard?

2018-08-06 Thread Ciprian Dorin Craciun
On Wed, Aug 1, 2018 at 7:32 PM Peter Lebbing wrote: > AFAIK, this is just systemd delegating passphrase querying to the > physically present user. I suppose if you could somehow influence where > it got the passphrase from, there might be a way to achieve it, but I > have no idea how. That's all

Re: pinentry-curses unusable with gpg-agent --no-detach

2015-02-05 Thread Ciprian Dorin Craciun
On Thu, Feb 5, 2015 at 6:38 PM, Matt Garman matthew.gar...@gmail.com wrote: Steps to demonstrate issue: (1) Start gpg-agent with --no-detach option (2) Make sure $DISPLAY is not set to force pinentry to fallback to curses (3) Attempt to decode a gpg-encrypted file to trigger pinentry [...]

Prioritizing secret keys when deciphering

2015-02-02 Thread Ciprian Dorin Craciun
I encounter a very anoing issue... If a certain packet is encrypted to multiple private keys, and I happen to have two (or multiple) of them in my secret keychain, then when decrypting, although GPG always tries them in the same order, the order is not the one I would prefer... Thus, is it

Re: Google releases beta OpenPGP code

2014-06-04 Thread Ciprian Dorin Craciun
On Wed, Jun 4, 2014 at 11:58 AM, Mark Rousell ma...@signal100.com wrote: On 04/06/2014 09:32, Werner Koch wrote: Maybe Google now fears that users move away from Gmail and to mitigate that they provide end-to-end so that they still have access to their user's traffic pattern. Oh perhaps they

Re: encryption/decryption without files

2012-09-20 Thread Ciprian Dorin Craciun
On Thu, Sep 13, 2012 at 7:16 PM, David Smith dave.sm...@st.com wrote: OK, so here's a list of issues: 3. If you're thinking of piping the output of an existing, unsecured editor into gpg, then that's not going to work, as the stdout will contain what it wants to print on the screen and the

Re: pipe passphrase to unlock key

2012-07-31 Thread Ciprian Dorin Craciun
On Tue, Jul 31, 2012 at 6:35 PM, Werner Koch w...@gnupg.org wrote: On Tue, 31 Jul 2012 12:54, ciprian.crac...@gmail.com said: Not a good idea, because GnuPG 2.1 requires the gpg-agent and won't see any private key stuff. Not necessarily if you use the `--batch`, `--no-use-agent`, or

Re: Paperkey (Was: Re: )

2010-03-12 Thread Ciprian Dorin, Craciun
I've used the `dtmx` tool to export some GPG keys (exactly a 4096 bits one) and it worked. What I did was something like: paperkey --secret-key ./key.gpg --output ./key.paperkey --output-type raw dmtxwrite --encoding 8 --format png --resolution 72 ./key.paperkey ./key.png

Re: gpg-agent --daemon running in foreground

2010-01-23 Thread Ciprian Dorin, Craciun
On Mon, Oct 12, 2009 at 3:57 PM, Ciprian Dorin, Craciun ciprian.crac...@gmail.com wrote: On Mon, Oct 12, 2009 at 4:08 PM, David Shaw ds...@jabberwocky.com wrote: On Oct 12, 2009, at 7:58 AM, Ciprian Dorin, Craciun wrote:   Hello all!   I'm facing the following problem: I need to run gpg

Re: gpg-agent --daemon running in foreground

2010-01-23 Thread Ciprian Dorin, Craciun
On Sat, Jan 23, 2010 at 11:59 AM, Ciprian Dorin, Craciun ciprian.crac...@gmail.com wrote: On Mon, Oct 12, 2009 at 3:57 PM, Ciprian Dorin, Craciun ciprian.crac...@gmail.com wrote: On Mon, Oct 12, 2009 at 4:08 PM, David Shaw ds...@jabberwocky.com wrote: On Oct 12, 2009, at 7:58 AM, Ciprian Dorin

GnuPG private key resilience against off-line brute-force attacks (was: Re: Backup of private key)

2009-11-28 Thread Ciprian Dorin, Craciun
(I'll try to start a new thread from the following quotes.) On Sat, Nov 28, 2009 at 8:50 AM, Robert J. Hansen r...@sixdemonbag.org wrote: Matt wrote: If I had a sufficiently good passphrase, would Google returning my secret key as the first hit result for every search for a day still be

Re: GnuPG private key resilience against off-line brute-force attacks (was: Re: Backup of private key)

2009-11-28 Thread Ciprian Dorin, Craciun
On Sat, Nov 28, 2009 at 5:47 PM, David Shaw ds...@jabberwocky.com wrote: On Nov 28, 2009, at 9:42 AM, Ciprian Dorin, Craciun wrote:   Maybe someone could clear this out (at least from GnuPG part). (My original post was related with both GnuPG an OpenSSH). ~~ Original post:   (I

Re: GnuPG private key resilience against off-line brute-force attacks (was: Re: Backup of private key)

2009-11-28 Thread Ciprian Dorin, Craciun
. On Sat, Nov 28, 2009 at 7:20 PM, Ciprian Dorin, Craciun ciprian.crac...@gmail.com wrote: On Sat, Nov 28, 2009 at 7:08 PM, Mario Castelán Castro mariocastelancas...@gmail.com wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 November 28th for gnupg-users@gnupg.org thread GnuPG private key

Re: Backup of private key

2009-11-25 Thread Ciprian Dorin, Craciun
On Wed, Nov 25, 2009 at 9:20 PM, Brian O'Kennedy brok...@gmail.com wrote: Hi All, This is a complete n00b question, but I still need to get an opinion on this. I've created myself a public/private key and got a bit concerned that if my harddrive fails, I lost the key and all data I've ever

Re: Howto For DNS Key publishing.

2009-10-30 Thread Ciprian Dorin, Craciun
On Fri, Oct 30, 2009 at 11:31 AM, Dan Mahoney, System Admin d...@prime.gushi.org wrote: On Thu, 29 Oct 2009, Ciprian Dorin, Craciun wrote: On Thu, Oct 29, 2009 at 7:52 AM, Dan Mahoney, System Admin d...@prime.gushi.org wrote: All, I've written a pretty conclusive howto on how to publish

gpg-agent --daemon running in foreground

2009-10-12 Thread Ciprian Dorin, Craciun
Hello all! I'm facing the following problem: I need to run gpg-agent, but without him going into background. Is there any solution to this one? Thanks, Ciprian. ___ Gnupg-users mailing list Gnupg-users@gnupg.org

Re: gpg-agent --daemon running in foreground

2009-10-12 Thread Ciprian Dorin, Craciun
On Mon, Oct 12, 2009 at 4:08 PM, David Shaw ds...@jabberwocky.com wrote: On Oct 12, 2009, at 7:58 AM, Ciprian Dorin, Craciun wrote:   Hello all!   I'm facing the following problem: I need to run gpg-agent, but without him going into background. Is there any solution to this one? I'm