Re: a step in the right direction

2018-01-16 Thread Duane Whitty
which stipulates what the penalties will be if the break the contract. Just my two cents and I'm sure it doesn't cover everything. Best Regards, Duane - -- Duane Whitty du...@nofroth.com -BEGIN PGP SIGNATURE- iQEcBAEBCAAGBQJaXlCfAAoJEOJfpr8UVxtkwgsH/3V+ZCc839yIENQD

Re: FAQ and GNU

2017-10-13 Thread Duane Whitty
ly, given the question you must have seen this one coming :-D Best Regards, Duane - -- Duane Whitty du...@nofroth.com -BEGIN PGP SIGNATURE- iQEcBAEBCAAGBQJZ4NRIAAoJEOJfpr8UVxtkKKoIAIOXzc5A4JePwqGmYE3q68XM WaQpSw09UM6aphbFBdsocGVZ7fuCXojKTtp0Ae

Re: OT: FAQ and GNU

2017-10-13 Thread Duane Whitty
I think it depends on the audience :-) > > > _______ Gnupg-users mailing > list Gnupg-users@gnupg.org > http://lists.gnupg.org/mailman/listinfo/gnupg-users > Best Regards, Duane - -- Duane Whitt

Re: Working with an Online and Offline Computer when using GnuPG - Best Practice?

2017-10-10 Thread Duane Whitty
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 17-10-10 02:04 PM, Daniel Kahn Gillmor wrote: > On Mon 2017-10-09 23:30:22 -0300, Duane Whitty wrote: >> After saying all that I recall reading an article by the >> Washington Post (if I recall correctly) that they use two >&g

Re: FAQ and GNU

2017-10-10 Thread Duane Whitty
ist Gnupg-users@gnupg.org > http://lists.gnupg.org/mailman/listinfo/gnupg-users > Rob, thanks for taking time out of your day and busy schedule for dealing with this issue. Too bad it is such a contentious issue for so many people. Thank you for your fairness and collaborative and community m

Re: FAQ and GNU

2017-10-10 Thread Duane Whitty
bad news is there is no single, consistent way to install GnuPG on Linux systems. The good news is that it’s usually installed by default, so nothing needs to be downloaded!" In this context does Linux mean any system running the Linux kernel or does it mean something else? The fourth matc

Re: FAQ and GNU

2017-10-10 Thread Duane Whitty
mailing > list Gnupg-users@gnupg.org > http://lists.gnupg.org/mailman/listinfo/gnupg-users > I believe FAQ should be left as is. Best Regards, Duane - -- Duane Whitty du...@nofroth.com -BEGIN PGP SIGNATURE- iQEcBAEBCAAGBQJZ3OknAAoJEOJfp

Re: Working with an Online and Offline Computer when using GnuPG - Best Practice?

2017-10-09 Thread Duane Whitty
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 17-10-09 11:30 PM, Duane Whitty wrote: > > > On 17-10-09 01:53 PM, Stefan Claas wrote: >> Hi all, > >> A question for the experts. > >> I plan to buy me a little Netbook next year, to use it as an >>

Re: Working with an Online and Offline Computer when using GnuPG - Best Practice?

2017-10-09 Thread Duane Whitty
There are lots of other details to think about (defense in depth) Best Regards, Duane - -- Duane Whitty du...@nofroth.com -BEGIN PGP SIGNATURE- iQEcBAEBCAAGBQJZ3DC6AAoJEOJfpr8UVxtki/YH/Rj7+gl6usd3twkGQ10VuboR qHBBpd+0zMrjfHDS713K50wexox0noCoUd7NTLt1pI8Lrl5c

Re: Houston, we have a problem

2017-09-26 Thread Duane Whitty
correctly if it can be applied > incorrectly. Murphy's Law applies. > I don't want my software or its developers acting like my big brother! >> being able to browse the keyserver directly is too useful for >> debugging to completely remove > > Indeed, but is i

Re: fingerprint of key

2017-08-17 Thread Duane Whitty
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 17-08-17 09:20 PM, Daniel Kahn Gillmor wrote: > On Mon 2017-08-14 22:12:18 -0300, Duane Whitty wrote: >> Actually one suggestion, the way options and commands are >> specified look the same. It might make things clearer if

Re: fingerprint of key

2017-08-17 Thread Duane Whitty
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 17-08-17 09:18 PM, Daniel Kahn Gillmor wrote: > On Mon 2017-08-14 21:50:13 -0300, Duane Whitty wrote: >> I perceive keys in my keyring as being ones I trust because of >> out-of-band confirmation and used for two-way

Re: fingerprint of key

2017-08-14 Thread Duane Whitty
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 17-08-14 09:50 PM, Duane Whitty wrote: > > > On 17-08-14 08:50 PM, Daniel Kahn Gillmor wrote: >> On Mon 2017-08-14 19:03:19 -0300, Duane Whitty wrote: >>> I did not and still do not want to import the oracle_vbox &g

Re: fingerprint of key

2017-08-14 Thread Duane Whitty
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 17-08-14 08:50 PM, Daniel Kahn Gillmor wrote: > On Mon 2017-08-14 19:03:19 -0300, Duane Whitty wrote: >> I did not and still do not want to import the oracle_vbox public >> key into my key ring. I am happy to download it and c

Re: fingerprint of key

2017-08-14 Thread Duane Whitty
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 17-08-14 05:58 PM, Daniel Kahn Gillmor wrote: > On Mon 2017-08-14 13:25:58 -0300, Duane Whitty wrote: >> Thanks for your response. So, what you are saying is that the >> man page is wrong ;-) > > I didn't think that

Re: fingerprint of key

2017-08-14 Thread Duane Whitty
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 17-08-14 12:14 PM, Daniel Kahn Gillmor wrote: > On Mon 2017-08-14 03:32:08 -0300, Duane Whitty wrote: >> I was recently trying to compare the fingerprint of a key I >> downloaded to its online stated value. I thought I shoul

fingerprint of key

2017-08-14 Thread Duane Whitty
eady has been. Best Regards, Duane - -- Duane Whitty du...@nofroth.com -BEGIN PGP SIGNATURE- iQEcBAEBCAAGBQJZkUPfAAoJEOJfpr8UVxtkLy8H/3ffsaDpy1YWfZNjRBTu3vGZ H/QrXGa7Mo7I9yFTojhyI9u9GCPzPu3sl/ZbvwGXEVpMoME5VuU8Fz5Dl1DGd9GF E1qT6Kk2L+H/eZiQNc4LFXjn3TQXNCIjq/HFiw7Eh/31eUc

Re: Fwd: Re: Fwd: Re: Question for app developers, like Enigmail etc. - Identicons

2017-06-12 Thread Duane Whitty
e compromised the minute you install said OS and are actually fulfilling the role of Mallory against yourself. This is to say that I believe Open Source is beneficial not that it is the complete solution. I would also add one word about USB sticks: It is very difficult to know if they've be

Re: Fwd: Re: Question for app developers, like Enigmail etc. - Identicons

2017-06-05 Thread Duane Whitty
ing signed/encrypted email back and forth to each other without them having done the work to ensure they are actually communicating with their intended parties. Trust takes work. Once the work on establishing identities has been done and trust has been established there is no need to remember k

Don't send encrypted messages to random users to test your gpg

2017-05-29 Thread Duane Whitty
unity :-) To test your setup try this link, https://emailselfdefense.fsf.org/en/ I haven't used it myself but unless someone from the list knows why it shouldn't be used it should fine. I also highly recommend reading https://www.gnupg.org/faq/gnupg-faq.html The above links are just to get start

Mailvelope browser extension for webmail

2017-05-29 Thread Duane Whitty
cator that shows how we can further improve Mailvelope. At this point, we’d like to thank Posteo for conducting the audit and thus their contribution to the Mailvelope project." I didn't see any Google related security information or notices. Best Regards, Duane -- Duane Whitty du...@nofr

Re: Smart card

2017-04-10 Thread Duane Whitty
mood a little and still explore what the possibility is, if any, of protecting data from the prying eyes of tier 1 actors who might not think that what you have is important enough to kill or injure you for but that they would try very hard to get by employing other efforts. I'm no

Re: How do you help someone to encrypted email (Re: How do you let your M.D. ...)

2016-12-02 Thread Duane Whitty
it's not the most secure method but maybe it is secure enough? Still doesn't solve the problem of having gnupg available and integrated on all the different platforms. (keeping fireproof suit on for a while :-) ) Thanks for your indulgence and patience :-) Best Regards, Duane - --

gnupg over Internet

2016-11-15 Thread Duane Whitty
ng a "road warrior" without the laptop. Let's say no hardware at all except my card reader and pin pad and maybe a near field radio id device and of course an android phone :-) which I have gnupg on but haven't figured out yet how to effectively use it. Any help is appreciated.

Re: What is a reliable way to backup/restore my keys and test?

2016-09-15 Thread Duane Whitty
es: >> >> $ gpg --import < priv.asc >> >> Import your public certificates: >> >> $ gpg --import < pub.asc > > > The above two steps should include the arguments "--import-options > import-local" just before &q

Re: What is a reliable way to backup/restore my keys and test?

2016-09-15 Thread Duane Whitty
process and they will be. Your private > certificates were exported, as were the trust assignments. > >> Once I have completed my OS upgrade how do I restore my keys and >> the trust levels assigned to them? > > See the above process. > >> I use Thunderb

What is a reliable way to backup/restore my keys and test?

2016-09-14 Thread Duane Whitty
, SHA1, RIPEMD160, SHA256, SHA384, SHA512, SHA224 Compression: Uncompressed, ZIP, ZLIB, BZIP2 Thunderbird 38.8.0 I hope this provides the required information. Please let me know if I should include something else. Best Regards, Duane - -- Duane Whitty du...@nofroth.com -BE