> > What shall happen in case a certain passphrase is compromised?
>
> Or worse yet, lost and forgotten?
> Is there an EMERGENCY show everything MASTER passphrase?
>
> If there is, who holds it? Isn't it a hole in the security model?

In our approach, this is entirely up to the user. I chose NOT to have
amaster passphrase on my clinic computer, but I have a reasonably secure
passphrase database on my (remotely accesible) server at home.

Usually there is no need for an emergency passphrase. Most of the data is
encrypted in a "standard" passphrase known to all doctors. It is up to the
patient / doctor to select a few highly sensitive pieces of information that
then are encrypted with a different passphrase / algorithm. A "hint phrase"
can optionally be stored to assist your memory regarding the passphrase.

Horst

Reply via email to