Re: gnutls heartbleed equivalent?

2014-06-02 Thread David Tomaschik
/mailman/listinfo/gnupg-users -- David Tomaschik OpenPGP: 0x5DEA789B http://systemoverlord.com da...@systemoverlord.com ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users

Re: locale bug in 1.4

2014-03-17 Thread David Tomaschik
://userbase.kde.org/Concepts/OpenPGP_Help_Spread OpenPGP: 7D82 FB9F D25A 2CE4 5241 6C37 BF4B 8EEF 1A57 1DF5 ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users -- David Tomaschik OpenPGP: 0x5DEA789B http

Re: Configure Errors

2014-03-14 Thread David Tomaschik
witha couple of them now and still get the same error. am i possibly missing something on my OS? many thanks sam ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users -- David Tomaschik

Re: cryptanalysis question: Does knowing some of the content of the message make the full message vulnerable to decryption?

2014-01-31 Thread David Tomaschik
to symmetric encryption methods as well? ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users -- David Tomaschik OpenPGP: 0x5DEA789B http://systemoverlord.com da...@systemoverlord.com

Re: USB key form-factor smart-card readers with pinpads?

2014-01-11 Thread David Tomaschik
On Sat, Jan 11, 2014 at 1:05 PM, Sam Kuper sam.ku...@uclmail.net wrote: On Jan 9, 2014 7:16 PM, David Tomaschik da...@systemoverlord.com wrote: if the machine you are using for crypto operations is compromised, you have lost (at least for the operations conducted while it is compromised

Re: USB key form-factor smart-card readers with pinpads?

2014-01-09 Thread David Tomaschik
would be grateful for pointers :) Regards, Sam ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users -- David Tomaschik OpenPGP: 0x5DEA789B http://systemoverlord.com da...@systemoverlord.com

Re: article about Air Gapped OpenPGP Key

2013-11-18 Thread David Tomaschik
Cheers! -Pete ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users -- David Tomaschik OpenPGP: 0x5DEA789B http://systemoverlord.com da...@systemoverlord.com

Re: 2.0.20 beta available

2013-04-24 Thread David Tomaschik
soon after 2.0.20. Shalom-Salam, Werner -- David Tomaschik OpenPGP: 0x5DEA789B http://systemoverlord.com da...@systemoverlord.com ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users

Re: The Lord of the Keys

2013-04-01 Thread David Tomaschik
and then you only need to unlock the GPG keys... -- David Tomaschik OpenPGP: 0x5DEA789B http://systemoverlord.com da...@systemoverlord.com ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users

Re: How difficult is it to break the OpenPGP 40 character long fingerprint?

2013-04-01 Thread David Tomaschik
? The longevity of any public key cryptosystem should probably be estimated in years or decades at the longest if you want any confidence in your answer. Regards, --dkg -- David Tomaschik OpenPGP: 0x5DEA789B http://systemoverlord.com da...@systemoverlord.com

Re: How difficult is it to break the OpenPGP 40 character long fingerprint?

2013-04-01 Thread David Tomaschik
On Mon, Apr 1, 2013 at 3:38 PM, Melvin Carvalho melvincarva...@gmail.comwrote: On 1 April 2013 22:50, David Tomaschik da...@systemoverlord.com wrote: On Mon, Apr 1, 2013 at 10:46 AM, Daniel Kahn Gillmor d...@fifthhorseman.net wrote: On 04/01/2013 12:24 PM, adrelanos wrote: gpg uses

Re: Patch for using GPG on 64 bit Matching

2013-01-23 Thread David Tomaschik
___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users -- David Tomaschik OpenPGP: 0x5DEA789B http://systemoverlord.com da...@systemoverlord.com ___ Gnupg-users mailing list Gnupg-users@gnupg.org

Rugged ID-000 form factor card reader?

2013-01-22 Thread David Tomaschik
in this way. Even better would be a new smart card with a form factor similar to the Yubikey Nano (https://www.yubico.com/products/yubikey-hardware/yubikey-nano/) but that might be a pipe dream. -- David Tomaschik OpenPGP: 0x5DEA789B http://systemoverlord.com da...@systemoverlord.com

Re: Problem trying to automate decrypt option

2012-10-17 Thread David Tomaschik
-users -- David Tomaschik OpenPGP: 0x5DEA789B http://systemoverlord.com da...@systemoverlord.com ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users

Re: OpenPGP smartcard, how vulnerable is it?

2012-08-15 Thread David Tomaschik
of numbers, letters and special chars). What am I missing? ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users -- David Tomaschik OpenPGP: 0x5DEA789B http://systemoverlord.com da...@systemoverlord.com

Bad Signatures when using check-sigs

2011-12-16 Thread David Tomaschik
not missing something obvious. -- David Tomaschik, RHCE, LPIC-1 System Administrator/Open Source Advocate OpenPGP: 0x5DEA789B http://systemoverlord.com da...@systemoverlord.com ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman

SCR3340 CardReader [Was: Re: Which ExpressCard/54?]

2011-11-19 Thread David Tomaschik
appreciated. -- David Tomaschik, RHCE, LPIC-1 System Administrator/Open Source Advocate OpenPGP: 0x5DEA789B http://systemoverlord.com da...@systemoverlord.com 2011-11-19 16:32:27 scdaemon[17659] listening on socket `/tmp/gpg-dNT4ZZ/S.scdaemon' 2011-11-19 16:32:27 scdaemon[17659] handler for fd -1

Re: use key, not passphrase, in symmetric encryption

2011-10-17 Thread David Tomaschik
instead of a tool designed for disk encryption? TrueCrypt is cross-platform and works well... if you're Windows-only, there's BitLocker, and for Linux there's LUKS/dm-crypt and eCryptFS. -- David Tomaschik, RHCE, LPIC-1 System Administrator/Open Source Advocate OpenPGP: 0x5DEA789B http

Re: Why revoke a key?

2011-10-11 Thread David Tomaschik
/nistpubs/800-63/SP800-63V1_0_2.pdf -- David Tomaschik, RHCE, LPIC-1 System Administrator/Open Source Advocate OpenPGP: 0x5DEA789B http://systemoverlord.com da...@systemoverlord.com ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org

Re: GPG with SMP?

2011-10-05 Thread David Tomaschik
, IIRC. -- David Tomaschik, RHCE, LPIC-1 System Administrator/Open Source Advocate OpenPGP: 0x5DEA789B http://systemoverlord.com da...@systemoverlord.com ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg

Re: Problem when decrypting PGP messages

2011-09-14 Thread David Tomaschik
is not a valid header, and is confusing gpg. Most likely, this is caused by the email client on the sending side wrapping the text. (Although maybe some receiving clients re-wrap text, I'm not aware of any.) Can you provide information on the client(s) in use? -- David Tomaschik, RHCE, LPIC-1 System

Re: OpenPGP card issues

2011-09-07 Thread David Tomaschik
-- David Tomaschik, RHCE, LPIC-1 System Administrator/Open Source Advocate OpenPGP: 0x5DEA789B http://systemoverlord.com da...@systemoverlord.com ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users

Re: Migrating to Smartcards

2011-08-30 Thread David Tomaschik
that would be an issue, but I can't be sure. Keep in mind that as long as the card is left in the reader, it would be considered unlocked -- do you want to leave that laying around? (It depends on your threat model, of course.) Thanks!    Richard -- David Tomaschik, RHCE, LPIC-1 System

Re: Migrating to Smartcards

2011-08-30 Thread David Tomaschik
On Tue, Aug 30, 2011 at 2:56 PM, Richard rich...@r-selected.de wrote: On Tue, Aug 30, 2011 at 20:49, David Tomaschik da...@systemoverlord.com wrote: No, you can store a primary key.  And you can use the 3 slots for any purpose (though I believe they must all tie to the same primary key

Re: Keys over 4096-bits

2011-08-26 Thread David Tomaschik
that nowadays more and more low-processing power devices are used. Such keys are at best a political statement and a good laugh for some NSA folks. Shalom-Salam,   Werner -- David Tomaschik, RHCE, LPIC-1 System Administrator/Open Source Advocate OpenPGP: 0x5DEA789B http://systemoverlord.com da

Re: Which release should we be using?

2011-08-26 Thread David Tomaschik
, wrong. Suggested readings: https://secure.wikimedia.org/wikipedia/en/wiki/Entropy_%28information_theory%29, https://secure.wikimedia.org/wikipedia/en/wiki/Password_strength and NIST publication 800-63. -- David Tomaschik, RHCE, LPIC-1 System Administrator/Open Source Advocate OpenPGP

Smartcard PIN may be shorter than passphrase?

2011-08-23 Thread David Tomaschik
for my regular PIN. (The admin PIN is somewhat longer.) Would this be considered a reasonable length? (Someone who can read the memory on a smart card by opening it up is NOT in my threat model -- if they can do that, they have much easier ways to coerce me into giving up my PIN.) -- David

Re: Smartcard PIN may be shorter than passphrase?

2011-08-23 Thread David Tomaschik
you can't do that instantly. Shalom-Salam,   Werner Thanks Werner! David -- David Tomaschik, RHCE, LPIC-1 System Administrator/Open Source Advocate OpenPGP: 0x5DEA789B http://systemoverlord.com da...@systemoverlord.com ___ Gnupg-users mailing

Re: Extract numbers from a key // wrong pgpdump link :-(

2011-08-23 Thread David Tomaschik
On 08/23/2011 06:52 PM, Faramir wrote: El 03-08-2011 9:40, ved...@nym.hush.com escribió: Sorry, wrong link extension, here is the correct one: http://www.pgpdump.net/ By the way, what would be required to run pgpdump locally? I guess there is no compiled version for windows... Best

Re: Scripting GPG Encryption

2011-08-10 Thread David Tomaschik
On 08/10/2011 12:32 PM, Smith, Greg E wrote: Hello, I am having an issue where we have set a custom home directory for GPG and configured the registry entry for HKCU\GNU\GNUPG\HomeDir=... The script functions fine when someone is logged into the system with the user account executing

Re: decrypt adding ^M characters at the end of each line

2011-08-02 Thread David Tomaschik
character. (Aka \r.) David -- David Tomaschik, RHCE, LPIC-1 System Administrator/Open Source Advocate OpenPGP: 0x5DEA789B http://systemoverlord.com da...@systemoverlord.com ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman

Re: Smartcard durability?

2011-07-28 Thread David Tomaschik
concerns from wallet storage, for instance? ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users -- David Tomaschik, RHCE, LPIC-1 System Administrator/Open Source Advocate OpenPGP: 0x5DEA789B

Re: Assertion failure from gnupg with enigmail 1.2

2011-07-12 Thread David Tomaschik
Sorry, this was intended to be sent to the entire list, but I composed it in a hurry my apologies. On Tue, Jul 12, 2011 at 4:24 PM, David Tomaschik da...@systemoverlord.com wrote: assert() kills the program if the value in the parentheses evaluates to FALSE.  In this case, that means

Re: 4096 bit keys

2011-03-22 Thread David Tomaschik
keys is nowhere near. (And by casually, I mean a difficulty similarly to what it takes to wiretap a phone.) [1] http://eprint.iacr.org/2010/006 -- David Tomaschik, RHCE, LPIC-1 System Administrator/Open Source Advocate OpenPGP: 0x5DEA789B http://systemoverlord.com da...@systemoverlord.com

Re: OpenPGP Card source

2011-03-03 Thread David Tomaschik
.  Ausnahmen regelt ein Bundesgesetz. -- David Tomaschik, RHCE, LPIC-1 System Administrator/Open Source Advocate OpenPGP: 0x5DEA789B http://systemoverlord.com da...@systemoverlord.com ___ Gnupg-users mailing list Gnupg-users@gnupg.org http

Re: Why do we use a different key to sign than to encrypt

2011-03-01 Thread David Tomaschik
where the RSA encryption was done to the plain text directly. Likewise, OpenPGP signing is done on a hash of the plain text. (Again, not on the plain text directly.) David -- David Tomaschik, RHCE, LPIC-1 System Administrator/Open Source Advocate OpenPGP: 0x5DEA789B http://systemoverlord.com da

Re: Question regarding shared keys

2011-02-28 Thread David Tomaschik
On 02/28/2011 05:38 PM, Denise Schmid wrote: Thanks all for your help. Now, the story gets even more funny: They claim to have used PGP split-key, then encrypted the files with a randomized key, then encrypted the key with individual keys. So far so bad. But now comes the best: They

Re: Restarting gnupg-agent inside X session

2011-02-28 Thread David Tomaschik
On 02/28/2011 06:17 PM, Marco Steinacher wrote: Hi, I use a OpenPGP smartcard with gnupg 2.0.14 and Ubuntu for different tasks. From time to time I face the following problem: The gpg-agent crashes for some reason after entering the PIN, 'ps' reports the daemon process as a zombie STAT

Re: Restarting gnupg-agent inside X session

2011-02-28 Thread David Tomaschik
On 02/28/2011 08:20 PM, Daniel Kahn Gillmor wrote: On 02/28/2011 06:49 PM, David Tomaschik wrote: Each process has its own copy of the environment inherited from its parent, so it's not possible to change the GPG_AGENT_INFO variable for all processes. You could start gpg-agent with --use

Re: PGP/MIME considered harmful for mobile

2011-02-27 Thread David Tomaschik
On 02/27/2011 12:21 PM, Robert J. Hansen wrote: On 2/26/11 9:24 PM, Jameson Rollins wrote: http://josefsson.org/inline-openpgp-considered-harmful.html * IT DOESN'T HANDLE ATTACHMENTS. That's fine with me: 95%+ of my messages don't require attachments. Any technology that can hit 95% of

Smart Card Physical Best Practices?

2011-02-26 Thread David Tomaschik
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 I've recently received my smart card, but was wondering what the best practices are, mainly from a physical standpoint. When I use it in my laptop reader, it sticks about 2 out of the side, and I have some concern about this (i.e., getting damaged

Re: SCR3310 reader working for root, but not scard group

2011-02-26 Thread David Tomaschik
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 I have a 3310 and with pcscd, I haven't even found the need to use the scard group. I have found that occasionally I have to restart scdaemon in order to get new readers/cards recognized. I haven't narrowed it down specifically yet. (I just got my

Re: SCR3310 reader working for root, but not scard group

2011-02-26 Thread David Tomaschik
On 02/26/2011 10:29 PM, Grant Olson wrote: On 02/26/2011 08:52 PM, David Tomaschik wrote: I have a 3310 and with pcscd, I haven't even found the need to use the scard group. I have found that occasionally I have to restart scdaemon in order to get new readers/cards recognized. I haven't

Re: Help with OpenPGP plugin in Mozilla Thunderbird and Claws Mail

2011-02-13 Thread David Tomaschik
attempt to decrypt the signature using your public key. If they are able to, they know your private key was used to produce the signature, and if you have kept control of your private key, it must have been signed by you. Hope that helps. -- David Tomaschik, RHCE, LPIC-1 System Administrator/Open

ID-000 SmartCard Form Factor

2011-01-28 Thread David Tomaschik
While I realize that the ID-1 (full size) cards can be used with card readers that support PIN entry, are there any other advantages/disadvantages to one size over the other? At present, I feel like the ID-000 form factor has more advantages because of the portability and the lower cost of the

SmartCard Import/Export

2011-01-26 Thread David Tomaschik
with any import taxes/customs trouble. -- David Tomaschik, RHCE, LPIC-1 GNU/Linux System Architect GPG: 0x5DEA789B da...@systemoverlord.com ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users

Re: Prosecution based on memory forensics

2011-01-13 Thread David Tomaschik
As usual, it all depends on your threat model. If you're really paranoid, don't use gpg-agent. :) -- David Tomaschik, RHCE, LPIC-1 GNU/Linux System Architect GPG: 0x5DEA789B da...@systemoverlord.com ___ Gnupg-users mailing list Gnupg-users@gnupg.org http

Re: [OT] broken threading via gmane

2010-12-12 Thread David Tomaschik
...@iem.pw.edu.pl874oaiocpp.fsf%25lukasz.stelm...@iem.pw.edu.pl -- Miłego dnia, Łukasz Stelmach ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users -- David Tomaschik, RHCE, LPIC-1 GNU/Linux

Re: Best Practices

2010-12-11 Thread David Tomaschik
, 2010 at 11:24 AM, Robert J. Hansen r...@sixdemonbag.orgwrote: On 12/10/2010 9:16 PM, David Tomaschik wrote: Are there any disadvantages to distinct signature encryption keys? None that I've found. Is the weakness in the hash used to sign the key internally, or just when it is used to sign

Best Practices

2010-12-09 Thread David Tomaschik
of this group might be useful in my next steps. Your help is appreciated. -- David Tomaschik, RHCE, LPIC-1 GNU/Linux System Architect da...@systemoverlord.com ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo