Re: [Enigmail] Key management by users, and key use by Enigmail/GPGWin/etc.

2014-08-07 Thread Philip Jackson
On 06/08/14 16:24, Robert J. Hansen wrote: I do not get your point here. My proposal is to operate the keyring from a USB stick. What is the difference with operating it from a smart card? Exactly what I said. USB is completely broken as far as security goes. A USB device cannot be made

Re: [Enigmail] Key management by users, and key use by Enigmail/GPGWin/etc.

2014-08-07 Thread Robert J. Hansen
Does the recent news about vulnerability of usb devices to attacks such as described in 'badusb' [*] mean that the usb reader into which the gnupg smart card is inserted is also vulnerable to exploits ? Sure. But the *kind* of exploits are different. If not, what is the essential difference

Re: [Enigmail] Key management by users, and key use by Enigmail/GPGWin/etc.

2014-08-07 Thread Olav Seyfarth
-BEGIN PGP SIGNED MESSAGE- Hash: RIPEMD160 Hi Philip, Does the recent news about vulnerability of usb devices to attacks such as described in 'badusb' [http://srlabs.de/badusb/] mean that the usb reader into which the gnupg smart card is inserted is also vulnerable to exploits?