Re: Attacks on encrypted communicxatiopn rising in Europe

2016-08-23 Thread Werner Koch
On Tue, 23 Aug 2016 21:37, joh...@vulcan.xs4all.nl said: > (German), the German and French government are attacking the right to > encrypt communication of their serfs. Also because of their violent Despite their common declaration to do something against the "evil" of encryption, the French and

Re: Attacks on encrypted communicxatiopn rising in Europe

2016-08-23 Thread Francesco Ariis
On Tue, Aug 23, 2016 at 10:26:17PM -0400, Robert J. Hansen wrote: > Some serious questions -- > > 1. Are you a privacy absolutist? > 2. If yes, why should we listen to you? Privacy and its boundaries are a well debated (and well worth to be debated) topic; keep in mind that any disc

Re: Attacks on encrypted communicxatiopn rising in Europe

2016-08-23 Thread Robert J. Hansen
> ... the German and French government are attacking the right to > encrypt communication of their serfs. I've got to ask a question. What would you have us do instead? For the last eight years I've worked in digital forensics. That's put me in a position to see the works of psychopaths up clos

RE: File Encrypted with Primary key

2016-08-23 Thread Scott Linnebur
Thanks everyone for your help on this. While I believe this is still an issue it wasn't the issue I was having. Apparently MoveIT was using the lowest level encryption algorithm allowed by my public key. I regenerated the key and removed the lower levels as options and all is fine. Thanks ag

Attacks on encrypted communicxatiopn rising in Europe

2016-08-23 Thread Johan Wevers
In http://www.heise.de/newsticker/meldung/Justiz-soll-verschluesselte-Terror-Kommunikation-auswerten-koennen-3302594.html (German), the German and French government are attacking the right to encrypt communication of their serfs. Also because of their violent anti-encryption opinion I was glad to s

Security through obscurity (was: OpenPGP Smartcard recommendations)

2016-08-23 Thread Peter Lebbing
On 23/08/16 12:51, Karol Babioch wrote: > However for me this mostly applies to the cryptographic concepts itself > and maybe software implementing them, not necessarily to physical > devices that have to withstand various forms of physical attacks. When > it comes to the real world, I'm not sure i

Re: SSH agent prompts for all passphrases

2016-08-23 Thread Karol Babioch
Hi, Am 23.08.2016 um 12:03 schrieb Peter Lebbing: > Or maybe the "Identity*" options in ssh_config help. After having played around with this for a while, I could solve this in the following way. I've created a pub file containing the public key of my smartcard and placed an appropriate IdentityF

Need Help decrypt HTML E-mail using OutlookPrivacyPlugin

2016-08-23 Thread David J
Hi, I've installed dejavusecurity/OutlookPrivacyPlugin to decrypt e-mails from outlook. It works well with encrypted text email but under features its says it can decrypt HTML e-mail. I'm collecting data from an online form and I want to send the email as a form with the data filled in. I encry

Re: OpenPGP Smartcard recommendations

2016-08-23 Thread Alexandre Pujol
Hi all, There is also the Nitrokey [1] that like the Yubikey is a smart-card in a USB stick. However Nitrokey has both software and hardware open source [2]. Regards, Alex [1] https://www.nitrokey.com/ [2] https://github.com/nitrokey On 23/08/16 01:54, Karol Babioch wrote: > Personally I absol

Re: OpenPGP Smartcard recommendations

2016-08-23 Thread Karol Babioch
Hi, since we are commenting here, I want to put out my two cents also, as this is a topic I'm deeply interested in. Am 23.08.2016 um 11:17 schrieb Peter Lebbing: > I was quite surprised by this blog post, by one small but, in my > eyes, significant part of it. A lot of the blog post seems not >

SSH agent prompts for all passphrases (was: Deleting SSH key(s) from agent)

2016-08-23 Thread Peter Lebbing
On 23/08/16 10:46, Karol Babioch wrote: > However, it is annoying to be prompted for passphrases for each key in > the keyring. This is even true for cases in which the public key of my > smartcard is the first and only entry in authorized_keys on a SSH server. Hm. I use both a smartcard and a

Re: SSH agent prompts for all passphrases

2016-08-23 Thread Peter Lebbing
On 23/08/16 11:51, Karol Babioch wrote: > Can I somehow control the order in which the client presents its keys to > the server? Is this something the agent controls, or the SSH client itself? I don't know, but perhaps that's best asked on an SSH mailing list? If it turns out that the agent has in

Re: OpenPGP Smartcard recommendations

2016-08-23 Thread Nicole Færber
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, as one from kernel concepts I need to apologize for the inconvenience, we had some major reworks in our infrastrcuture these days. Now things start to get settled again, mail should work and the website should also be up again - but there might

Re: SSH agent prompts for all passphrases

2016-08-23 Thread Karol Babioch
Hi again, Am 23.08.2016 um 11:29 schrieb Peter Lebbing: > Hm. I use both a smartcard and an encrypted on-disk key, and am > never prompted for a passphrase for a key that isn't listed in > authorized_keys. Ok, it was my mistake. Looking through the verbose output of the SSH client, I realized

Re: OpenPGP Smartcard recommendations

2016-08-23 Thread Peter Lebbing
On 23/08/16 02:54, Karol Babioch wrote: > P.S.: I should also mention that there is some debate about the open > source nature of the YubiKey 4, since its firmware is not open to > review any longer. Should this be a criterion for you, you have to > go with another solution. You'll find details o

Re: Deleting SSH key(s) from agent

2016-08-23 Thread Karol Babioch
Hi, Am 23.08.2016 um 10:36 schrieb Peter Lebbing: > If I'm mistaken, I'd like to know. But I suspect the system was > correctly designed to thwart such a thing. I'm pretty sure you are right, so this is not my concern. > So I don't think there is a need to ensure the correct key is used. Howeve

Re: Deleting SSH key(s) from agent

2016-08-23 Thread Peter Lebbing
On 23/08/16 10:20, Karol Babioch wrote: > How are you guys dealing with multiple SSH keys while making sure the > correct one is being used? I don't make sure the correct one is used. The challenge that is signed with your private key is based on data provided by both the server and the client. I

Re: Deleting SSH key(s) from agent

2016-08-23 Thread Karol Babioch
Hi, Am 21.08.2016 um 12:27 schrieb Peter Lebbing: > Let me answer by example: Thank you very much. I even knew about gpg-connect-agent, but didn't connect the dots. I was too focussed on getting it to work through the ssh-add interface. It does indeed work as outlined. However it seems to be mor