Re: OpenPGP card not available

2024-04-09 Thread Dan Fandrich
I added "disable-ccid" to scdaemon.conf and gpg now works even though pcscd is running. Thanks for the help. Dan ___ Gnupg-users mailing list Gnupg-users@gnupg.org https://lists.gnupg.org/mailman/listinfo/gnupg-users

OpenPGP card not available

2024-04-09 Thread Dan Fandrich
nked against libpthread.so.0 but the failing one is linked against libnpth.so.0, but that seems to have to do with locking which I wouldn't expect to make difference with a simple local test. I was hoping to bisect to the problem except that the 2.3 and

OpenPGP card not available

2024-04-08 Thread Dan Fandrich
nked against libpthread.so.0 but the failing one is linked against libnpth.so.0, but that seems to have to do with locking which I wouldn't expect to make difference with a simple local test. I was hoping to bisect to the problem except that the 2.3 and

Re: Questions re auto-key-locate

2022-02-15 Thread Dan Mahoney via Gnupg-users
> On Feb 15, 2022, at 2:45 PM, Andrew Gallagher wrote: > > >> On 15 Feb 2022, at 21:46, Dan Mahoney (Gushi) via Gnupg-users >> wrote: >> >> Since the debacle a few years ago with the SKS keyserver denial-of-service >> attack, the keyservers

Questions re auto-key-locate

2022-02-15 Thread Dan Mahoney (Gushi) via Gnupg-users
n@ key into our keyring is not helpful either, unless we "faked it" by attempting to encrypt a message to that address, then discarded it. Is there another way forward? The normal things for auto-key-locate don't seem to help here. I'm open to ideas. -Dan (PS: on gnupg.

Ideas on raising donations for GnuPG, Gpg4win, and g10 code

2019-04-30 Thread Dan Bryant
I was on Amazon Smile today and noticed quite a few FOSS projects were available to select as the source of my amazon shopping proceeds. Also thought that registering gnupg.org, gpg4win.org and g10code.com in the Brave Rewards program might be an interesting way to allow GnuPG to accept small concu

Re: Can I use my Microsoft Outlook S/MIME certificate with gpgsm.exe ?

2019-03-14 Thread Dan Bryant
Thanks, I checked the following per your advice 1. Are any of the certs ECC? No, they all appear to be RSA keys. 2. Has the org root cert been imported? I believe so, yes. There are three certs in the chain. My s/MIME cert, it's parent, and its "grandparent". Both gpgsm and the Windows Cert

Can I use my Microsoft Outlook S/MIME certificate with gpgsm.exe ?

2019-03-13 Thread Dan Bryant
So I work for a large company that has their own internal CA and maintains their own set of S/MIME certificates. We periodically have to re-enroll in S/MIME and import the certificate into Microsoft Outlook to have encrypt / sign functionality. This time when I enrolled for my recent certificate,

Re: Breaking changes

2018-05-23 Thread Dan Kegel
but even just matching 14.04's would make sense to a lot of people. Also, gnupg.org should add a web page like https://www.gnupg.org/release-end-of-life that lays out the EOL for all released versions; the only one with a clear EOL is 2.0.x, and that's a bit buried in text on the front page. - Dan

Re: Breaking changes

2018-05-22 Thread Dan Kegel
3 to 6 months)? That would avoid poking classic users in the eye too hard, and give time for them to get used to the idea. - Dan ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users

Re: Don't Panic.

2018-05-14 Thread Dan Kegel
t consider unticking it.) - Dan On Mon, May 14, 2018 at 12:27 AM, Robert J. Hansen wrote: > [taps the mike] > > Hi. I maintain the official GnuPG FAQ. So let me start off by > answering a question that is certainly about to be asked a lot: "Should > we be worried about Ope

Re: How can we utilize latest GPG from RPM repository?

2018-02-22 Thread Dan Kegel
n repositories for four redhat-ish distros and two debian-ish distros; on Ubuntu, I was able to walk down the path of using it a bit, looks a bit rusty, but see https://github.com/OpenSCAP/scap-security-guide So it doesn't seem to be RHEL-only. (They

Re: How can we utilize latest GPG from RPM repository?

2018-02-21 Thread Dan Kegel
its a lot easier than building the latest gnupg release yourself... and is less likely to break things. - Dan ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users

Re: Using GnuPG when switching users

2018-01-31 Thread Dan Horne
happy with, but it was only temporary as we don't require an interactive passphrase following key creation. On 1 February 2018 at 05:00, Daniel Kahn Gillmor wrote: > On Mon 2018-01-29 15:44:56 +1300, Dan Horne wrote: > > Has someone got a workaround? I need to be able to use "su&

[no subject]

2018-01-28 Thread Dan Horne
Hi I'm using GnuPG 2.0.29 on Solaris. This specific version is being used because it's the only one we could get installed and working. I'm trying to generate keys from a user I have su'd to, but I get the following error: gpg-agent[23024]: command get_passphrase failed: Permission denied gpg:

Using GnuPG when switching users

2018-01-28 Thread Dan Horne
Hi I'm using GnuPG 2.0.29 on Solaris. This specific version is being used because it's the only one we could get installed and working. I'm trying to generate keys from a user I have su'd to, but I get the following error: gpg-agent[23024]: command get_passphrase failed: Permission denied gpg:

Re: Will gpg 1.x remain supported for the foreseeable future?

2018-01-20 Thread Dan Kegel
On Sat, Jan 20, 2018 at 4:08 PM, Todd Zullinger wrote: > I think that's https://dev.gnupg.org/T2290 Thanks. Say, anyone know how to get bug tracker problems resolved? Somehow my email address there lacks a dot before .com, so I can't get confirmation

Re: Will gpg 1.x remain supported for the foreseeable future?

2018-01-20 Thread Dan Kegel
On Thu, Jan 18, 2018 at 7:58 PM, Dan Kegel wrote: >> The keys referred to via signed-by are the only acceptable keys for the >> associated apt repo. >> >> does that make sense? > > That'd be great if it worked. Since it's hard to explain what's bro

Re: Will gpg 1.x remain supported for the foreseeable future?

2018-01-18 Thread Dan Kegel
via signed-by are the only acceptable keys for the > associated apt repo. > > does that make sense? That'd be great if it worked. Since it's hard to explain what's broken without a simple script showing exactly what I'm doing, let's just hold that thought until I

Re: Will gpg 1.x remain supported for the foreseeable future?

2018-01-18 Thread Dan Kegel
On Wed, Jan 17, 2018 at 8:58 PM, Dan Kegel wrote: > Here's the bit where it explodes, > > + sudo GNUPGHOME=/tmp/obs_localbuild_gpghome_dank.tmp > APT_CONFIG=/home/dank/src/obs/foo.tmp/etc/apt.conf apt-get -q -q > update > inside VerifyGetSigners > Preparing to exec:

Re: Will gpg 1.x remain supported for the foreseeable future?

2018-01-17 Thread Dan Kegel
apt-key works, or just plain being dumb. My next move is probably reading apt-key and trying to understand it. Alternately, I could try ripping out all the gpg1 support in my scripts. That probably won't help, but would be satisfying :-) - Dan ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users

Re: Will gpg 1.x remain supported for the foreseeable future?

2018-01-17 Thread Dan Kegel
On Tue, Jan 16, 2018 at 8:31 PM, Daniel Kahn Gillmor wrote: > On Tue 2018-01-16 20:10:38 -0800, Dan Kegel wrote: > > When I try to use gpg to manipulate secure apt repositories in the > > real world, my head explodes. > > hi there! what kind of manipulation are yo

Re: Will gpg 1.x remain supported for the foreseeable future?

2018-01-16 Thread Dan Kegel
ures will probably not be backported > * if you need 1.4 support, contact g10 Code GmbH Thanks. When I try to use gpg to manipulate secure apt repositories in the real world, my head explodes. I'm sure it will all seem reasonable after I figure things out. I've only been at i

Will gpg 1.x remain supported for the foreseeable future?

2018-01-16 Thread Dan Kegel
fact that even the latest apt from debian does not support version 2's keybox format, so I had to drop back to gpg version 1 anyway. Is version 1 going to remain available, I hope? Version 2 simply seems a poor fit for scripting. Thanks, Dan ___ G

Re: GnuPGv2 & 'pinentry' on Linux w/ remote access

2017-11-07 Thread Dan Kegel
solve? I'm curious, too. It sure makes scripting hard. - Dan ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users

Re: Verify that the file is from who I expect it to be from

2017-10-29 Thread Dan Horne
Thanks. I exported my keys to ~/.gnupg/trustedkeys.gpg. I tried gpgv2 but got the following bash-3.2$ gpgv2 declaration.pgp gpgv: verify signatures failed: Unexpected error Adding --verbose did not affect this (Note this is a OpenCSW install) However, if I simply decrypt the file I get confirmat

Re: Verify that the file is from who I expect it to be from

2017-10-26 Thread Dan Horne
e data, usually by long key > ID IIRC. You have to make sure the key that signed the data is the key that > you expect, basically. If you need something more in-depth, there are many > more qualified individuals to assist on the list. > > On October 26, 2017 7:52:33 PM EDT, Dan Ho

Re: Verify that the file is from who I expect it to be from

2017-10-26 Thread Dan Horne
Thanks - I get the line saying "good signature" i n my message, but are you saying that I have to grep the output for the message and the email address of the encryptor? ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/lis

Verify that the file is from who I expect it to be from

2017-10-26 Thread Dan Horne
Hi all maybe I'm missing something, but how do I verify not only that an encrypted file is signed, but that it is signed by the party I expect to have signed it? In other words, if two parties can supply a file with the same name I want to make sure that when I think I'm dealing with a file from p

Re: Automating and integrating GPG

2017-09-18 Thread Dan Kegel
mated test that sometimes fails on slow systems like raspberry pi because of my poor transparent wrapper around the gpg agent. It is somewhat obscured by site-specific stuff (e.g. it uses gpg via apt). I could try to do a clean demo without apt sometime if that would be helpful. - Dan __

Re: Automating and integrating GPG

2017-09-18 Thread Dan Kegel
On Mon, Sep 18, 2017 at 2:45 PM, Daniel Kahn Gillmor wrote: > GnuPG upstream developers tend to recommend the use of GPGME for system > integration projects that require a stable interface. dpkg does that, but it doesn't help people trying to automate dpkg

"Insecure memory" (yes setuid set) and "get_passphrase failed"

2017-09-04 Thread Dan Horne
-rwxr-xr-x 1 root bin58004 Jul 11 2011 /opt/csw/bin/pinentry-curses It still doesn't work After a bit more Googling, I tried adding the following to my gpg.conf file, but it caused a syntax error: pinentry-program /opt/csw/bin/pinentry-curses Any advice

Re: Newbie can't get --passphrase option to work

2017-05-16 Thread Dan Kegel
il/058158.html https://lists.gnupg.org/pipermail/gnupg-users/2017-April/058162.html describe my travails. It was several days of learning curve. In fairness, I needed a solution that worked with all versions of gpg that shipped with any LTS version of ubuntu, not just the current release, which made things

Re: Newbie can't get --passphrase option to work

2017-05-13 Thread Dan Kegel
Did you see my walkthrough of all the problems I ran into while getting gpg to not prompt? https://lists.gnupg.org/pipermail/gnupg-users/2017-April/058158.html https://lists.gnupg.org/pipermail/gnupg-users/2017-April/058162.html That's for Linux, but it might still have a trick you're missing. _

Re: Unattended use of gpg across a wide range of gpg versions, Ubuntu edition. --debug-quick-random taking evasive action.

2017-04-30 Thread Dan Kegel
chmod +x test-script.sh rm -rf /tmp/gpgtest-* export GNUPGHOME=$(mktemp -d /tmp/gpgtest-XXX.tmp) echo "allow-loopback-pinentry" > $GNUPGHOME/gpg-agent.conf gpg-agent --daemon ./test-script.sh rm -rf $GNUPGHOME -- snip -- On Sat, Apr 29, 2017 at 9:14 PM, Dan Kegel wrote: > tl;

Unattended use of gpg across a wide range of gpg versions, Ubuntu edition. --debug-quick-random taking evasive action.

2017-04-29 Thread Dan Kegel
tl;dr: anyone know what's up with --debug-quick-random? Also, handy script for unattended key generation across many versions of gpg. Hi all. This topic has been beaten to death on many forums and in many bug reports, but here's a user report from the field that sums up what works. It's mostly

Re: OSX: How to install gpg without Admin password

2015-08-30 Thread Dan Bryant
ome/xyz/pinentry-mac.app/Contents/MacOS/pinentry-mac > > -Patrick > > On 29.08.15 19:13, Dan Bryant wrote: >> OK, this worked in getting the binaries extracted and by setting PATH >> and DYNLD_LIBRARY_PATH I can get the bins to load and dump version >> information... SUCCESS..

Re: OSX: How to install gpg without Admin password

2015-08-29 Thread Dan Bryant
, libexecdir with gpgconf (gpgconf.conf) but I can't seem to figure out how to convice gpg to look in nonstandard paths for binaries and libraries. Seems to be ignoring PATH environment. Suggestions? On Thu, Aug 27, 2015 at 1:31 AM, Patrick Brunschwig wrote: > On 26.08.15 17:16, Dan Bryant wro

Re: OSX: How to install gpg without Admin password

2015-08-26 Thread Dan Bryant
, Dan Bryant wrote: > I have a monitored OS X laptop that I would like to put GNU Privacy > Guard (gpg) on. Of course I can't because I don't have Admin rights, > but I was hoping there is a way to install it in user space through a > virtual environment or chroot, or some

OSX: How to install gpg without Admin password

2015-08-26 Thread Dan Bryant
I have a monitored OS X laptop that I would like to put GNU Privacy Guard (gpg) on. Of course I can't because I don't have Admin rights, but I was hoping there is a way to install it in user space through a virtual environment or chroot, or some other wizardry, or by exacting the package files. Ob

Re: Generating GnuPG S/MINE key pair

2015-05-05 Thread Dan Bryant
*SOLVED* On Tue, Apr 28, 2015 at 11:12 AM, Dan Bryant wrote: > OK... I'm apparently suffering from a bad gpgsm setup. According to > the 2011 post > (https://lists.gnupg.org/pipermail/gnupg-devel/2011-March/025989.html) > the following command, should just work: >gpg

Re: Generating GnuPG S/MINE key pair

2015-04-28 Thread Dan Bryant
OK... I'm apparently suffering from a bad gpgsm setup. According to the 2011 post (https://lists.gnupg.org/pipermail/gnupg-devel/2011-March/025989.html) the following command, should just work: gpgsm --gen-key | gpgsm --import Not for me... I get gpgsm: problem looking for existing certific

Re: Generating GnuPG S/MINE key pair

2015-04-27 Thread Dan Bryant
xt: 281.760.4296 On Mon, Apr 27, 2015 at 9:22 PM, Dan Bryant wrote: > OK... I found some very old posts about this... don't know how much still > holds. > -- https://lists.gnupg.org/pipermail/gnupg-devel/2011-June/026126.html > > This guide says: > 1. Convert rootCA.pem t

Re: Generating GnuPG S/MINE key pair

2015-04-27 Thread Dan Bryant
2.2.4) - gpgsm (GnuPG) 2.1.3 On Mon, Apr 27, 2015 at 3:07 PM, Dan Bryant wrote: > TL;DR: gpgsm import fails with "no issuer found in certificate" > > I'm trying to generate a key-pair for GnuPG S/MINE strictly for > instructional reasons. I'll concede that I'm u

Generating GnuPG S/MINE key pair

2015-04-27 Thread Dan Bryant
TL;DR: gpgsm import fails with "no issuer found in certificate" I'm trying to generate a key-pair for GnuPG S/MINE strictly for instructional reasons. I'll concede that I'm using a weak CA, but I'm trying to image how the CA maintainers do this task as well. So, for my instruction, I'm trying to

Re: Fwd: GNU hackers discover HACIENDA government surveillance and give us a way to fight back

2014-08-27 Thread dan
are and must be shared amongst providers plus the providers' paymasters, and on and on. That these are possible is worrisome; that they are widely built into services which promise "convenience" is the Pied Piper institutionalized. As I wrote elsewhere(*), we are becoming a society of infor

Re: Fwd: GNU hackers discover HACIENDA government surveillance and give us a way to fight back

2014-08-23 Thread dan
short, I have nowhere to hide from you. This being the gnupg list, we are likely now in a rat hole, but if we are not yet there, then let me ask a question: Many's the member of this list who posts under a pseudonym. Is pseudonymous postin

Re: Fwd: GNU hackers discover HACIENDA government surveillance and give us a way to fight back

2014-08-23 Thread dan
n everything, does not the very concept of private information fade, per se? I believe it does. We Are All Intelligence Officers Now http://geer.tinho.net/geer.rsa.28ii14.txt --dan ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg

Re: It's 2014. Are we there yet?

2014-04-11 Thread dan
mobile phone. Small sample,... --dan ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users

Re: It's 2014. Are we there yet?

2014-04-10 Thread dan
, so why would anyone ever render HTML e-mail at all? Apologies, --dan ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users

Re: How to do pinentry in same screen as gpg

2014-01-03 Thread Dan Mahoney, System Admin
On Fri, 3 Jan 2014, Hauke Laging wrote: Am Fr 03.01.2014, 01:14:22 schrieb Dan Mahoney, System Admin: It basically works perfectly with gpg1, where I can get an inline prompt for a password, but gpg2 falls short where it tries to set up some kind of a unix-socket connection to a pinentry

Re: How to do pinentry in same screen as gpg

2014-01-03 Thread Dan Mahoney, System Admin
On Fri, 3 Jan 2014, Hauke Laging wrote: Am Fr 03.01.2014, 01:14:22 schrieb Dan Mahoney, System Admin: It basically works perfectly with gpg1, where I can get an inline prompt for a password, but gpg2 falls short where it tries to set up some kind of a unix-socket connection to a pinentry

How to do pinentry in same screen as gpg

2014-01-03 Thread Dan Mahoney, System Admin
G had some method of simply saying "hey, I can't find a place to spawn this pinentry, and could exit cleanly." Thoughts are welcome. -Dan -- Dan Mahoney Techie, Sysadmin, WebGeek Gushi on efnet/undernet IRC ICQ: 13735144 AIM: LarpGM Site: http://www.gushi.org ---

Re: UK Guardian newspaper publishes USA NSA papers

2013-12-07 Thread dan
s only 3.43, as found in Bakhshandeh, Samadi, Azimifar & Schaeffer, "Degrees of Separation in Social Networks," 2011 http://www.aaai.org/ocs/index.php/SOCS/SOCS11/paper/view/4031 "Allowed three hops" is closer to a grand mal seizure than a twitch. For a sideline, look up "p

Re: [tor-talk] BitMail.sf.net v 0.6 - Secure Encrypting Email Client

2013-11-17 Thread dan
the compiler. --dan ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users

Re: RNG: is it possible to spoil /dev/random by seeding it from (evil) TRNGs (was: howto secure older keys after the recent attacks)

2012-10-09 Thread dan
#x27;t get sold. but > given that rigorous testing of the TRNG circuit > is so expensive, it's my guess that the CPU > vendor surely must just unwittingly ship the > CPUs that happen to have obscurely bad TRNGs. --dan ___ Gnupg

Re: [gnupg-users] Re: Future of GnuPG 1.x.x?

2012-08-05 Thread Dan Mahoney, System Admin
this a blocking factor for moving to 2.0. When 1.4 support ends, expect an EOL date to be announced far in advance and a lot of help given to people who need to migrate to 2.0. See above. -Dan -- Dan Mahoney Techie, Sysadmin, WebGeek Gushi on efnet/undernet IRC ICQ: 13735144

Re: Reply-to netiquette (was [META] please start To: with gnupg-users@gnupg.org...)

2012-02-01 Thread dan
Turing-Complete language which characteristic, if I need to say it, means that security, a variant of the halting problem, is formally undecideable. --dan ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users

Re: [META] please start To: with gnupg-users@gnupg.org, i.e.: To: gnupg-users@gnupg.org

2012-01-28 Thread dan
d also vote for the list having a "reply-to" header. The above applies to all mailing lists, including here. I can cope; this is just my ask. Please and thank you, --dan ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.o

Re: Short ID Collision

2012-01-05 Thread Dan McGee
://pgp.mit.edu:11371/pks/lookup?op=index&options=mr&search=0xE19DAA50&exact=on This is totally unacceptable in my opinion, why do we have such broken infrastructure that it cannot support a simple lookup like this? -Dan ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users

Re: Gnupg file formats

2011-12-01 Thread Dan McGee
or is it documented elsewhere? > > Read section 4.2 of RFC-4880.  The length header encoding is a bit > complicate. The pgpdump source code may be a bit more easy to grasp if you just want to understand the file format. http://www.mew.org/~kazu/proj/pgpdump/en/ -Dan _

Re: STEED - Usable end-to-end encryption

2011-10-24 Thread dan
eir doors > condemning Total Information Awareness and EFF stickers on their laptops. > You got that right, Brother. To be more pointed, how many folks on this list carry a cell phone? --dan ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users

Marking a key as "don't export"?

2011-08-25 Thread Dan McGee
e the machine. The only operation it will ever be used in is lsigning various other public keys. -Dan ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users

Re: Which release should we be using?

2011-08-22 Thread Dan McGee
anagement program like Keepass makes transfer via the clipboard easy and relatively safe (clearing it after 10 seconds), so that doesn't sound like the safety of "no passphrase at all". -Dan ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users

Re: Creating a quickly expiring signature

2011-07-28 Thread Dan McGee
On Thu, Jul 28, 2011 at 5:04 PM, David Shaw wrote: > On Jul 28, 2011, at 4:49 PM, Dan McGee wrote: > >> I wanted to test behavior of an application with an expired signature, >> but using `--ask-sig-expire` don't seem to be granular enough. The >> minimum I can s

Creating a quickly expiring signature

2011-07-28 Thread Dan McGee
cimal values are not accepted, nor seconds, minutes, or hours. -Dan ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users

Re: Generate digest and signature seperately

2011-06-13 Thread Dan McGee
see a reasonable and secure workflow for this? I did suggest [2] signing package hashes as one possible option, after looking into agent forwarding and discovering that doesn't seem to be a workable option at this point. -Dan [1] http://www.archlinux.org/packages/community/i686/sage-mathema

Re: Working with a system-shared keyring

2011-06-03 Thread Dan McGee
ngine, and thus change >  the executable program and configuration directory to be used.  You can >  make these changes the default or set them for some contexts >  individually. > >   -- Function: gpgme_error_t gpgme_set_engine_info Yes, we are doing this already and are setting the hom

Working with a system-shared keyring

2011-06-02 Thread Dan McGee
o run with --lock-never in a read-only mode? Any feedback is welcome, thanks in advance! -Dan $ sudo gpg --homedir /etc/pacman.d/gnupg --verify /home/makepkg/packages/libmysqlclient-5.5.12-1-x86_64.pkg.tar.xz.sig gpg: WARNING: unsafe permissions on homedir `/etc/pacman.d/gnupg' gpg: Signature

Re: Slightly OFF TOPIC - Traffic analysis...in reverse?

2011-05-02 Thread dan
mean). As it happens, everyone I call assumes it is me as I am the only one who chooses that. --dan ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users

Re: Deniability

2011-03-23 Thread dan
ictly speaking) possible a hundred years ago, but also extr > emely unrealistic. The "23andme.com" folks claim that their genetic screening thing is liberating people by connecting them to relatives that they did not know they had. I, for one, have a lot of relatives that I don&#

Re: Deniability

2011-03-23 Thread dan
s. May I borrow this and | present it to others (with attribution)? Yes, of course. --dan ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users

Re: Deniability

2011-03-22 Thread dan
correct. My own definition of privacy evolves, but as of now is this: Privacy is the effective capacity to misrepresent oneself. and, semi-orthogonally, Security is the absence of unmitigatable surprise. YMMV, --dan ___ Gnupg-users mailing

Re: Deniability

2011-03-22 Thread dan
ant. If zero-summed-ness is an actual fact of nature, then I'll choose more privacy and less security as the Internet-of-Things approaches. --dan A conservative is a socialist who worships order. A liberal is a socialist who worships safety.

Re: Deniability

2011-03-22 Thread dan
I don't think anyone was suggesting that adroit use of PGP/GPG is a talisman against those who wield lead pipes and want what they want. Not that there isn't a movie script in that line of thought... --dan ___ Gnupg-users mailing list G

Re: deniability

2011-03-21 Thread dan
| | 2. Randomly send messages that can't be decrypted to random recipients |to obscure matters. The adversary would have to cope with the fact |that I have stuff to hide. :) | Ah. Spam as a covert channel. Tell me that this isn't already do

Re: What is the benefit of signing an encrypted email

2011-01-11 Thread dan
If one is a purist, then one wants sign>encrypt>sign See http://world.std.com/~dtd/#sign_encrypt --dan ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users

Security considerations: CAST-128

2010-10-21 Thread Dan Cowsill
bject appear to be quite scarce, I come to you, O list. If anyone can clarify or elaborate on the security considerations of CAST-128, it would be greatly appreciated. Thanks, Dan [1]http://www.springerlink.com/content/978-3-642-04158-7/ -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.10 (Mi

Changing secret key encryption algorithms

2010-10-21 Thread Dan Cowsill
you have any further information, want to correct or otherwise comment on the above, feel free. Regards, Dan [1]http://www.spywarewarrior.com/uiuc/ss/sec-key/sec-key.htm -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.10 (MingW32) Comment: Using GnuPG with Mozilla - http://enigmail.mo

Re: Confirmation for cached passphrases useful?

2010-10-14 Thread Dan Cowsill
On 13/10/2010 4:02 PM, MFPA wrote: > The user can type their password once per session into a text file and > paste it every time it is requested. This reduces the annoyance factor > and does not train the user to constantly re-type the passphrase. > I use a program called KeePass to keep track of

Paranoid People's User Group?

2010-10-13 Thread Dan Cowsill
Hi everyone, Almost-but-not-quite my first post to this list. I am very interested in encryption technologies, and PGP in particular. Of course, this is only a hobby and I don't have any trade secrets or international intrigues to protect, so that leaves me at a bit of a disadvantage when it com

Re: "No-Keyserver" (and other) flags on keys

2010-06-29 Thread Dan Mahoney, System Admin
ay in fact do this, but --search does not. Is there a way to make that work? -- "Ca. Tas. Tro. Phy." -John Smedley, March 28th 1998, 3AM Dan Mahoney Techie, Sysadmin, WebGeek Gushi on efnet/undernet IRC ICQ: 13735144 AIM: LarpGM Site:

Re: "No-Keyserver" (and other) flags on keys

2010-06-27 Thread Dan Mahoney, System Admin
verifying selfsigs before publication, or do you think they should remain "dumb"? Both imply some problems, but your statement as to keyservers not doing crypto didn't seem to imply whether you're for or against it, and I'm curious. -Dan -- Dan Mahoney

Re: "No-Keyserver" (and other) flags on keys

2010-06-27 Thread Dan Mahoney, System Admin
On Sun, 27 Jun 2010, David Shaw wrote: On Jun 27, 2010, at 7:50 PM, Dan Mahoney, System Admin wrote: It's effectively a no-op though, as no server supports it. I'm looking into making mods to at least one server type (we run one locally at work), and commit them upstream. If I&

Re: "No-Keyserver" (and other) flags on keys

2010-06-27 Thread Dan Mahoney, System Admin
as simply a "keyservers should throw this away" flag, where a user might choose to publish on his website, his .plan file, on his business cards, in DNS, or via LDAP or S/Mime autodiscovery.) -Dan -- "Hitler, Satan, those Hanson kids, anything. Just not the curious anteate

Re: "No-Keyserver" (and other) flags on keys

2010-06-27 Thread Dan Mahoney, System Admin
On Sun, 27 Jun 2010, David Shaw wrote: On Jun 27, 2010, at 3:58 PM, Dan Mahoney, System Admin wrote: All, How difficult would it be to propose some kind of extension flag to the PGP key format that in essence says "don't publish me to a keyserver". Note that I'm aski

"No-Keyserver" (and other) flags on keys

2010-06-27 Thread Dan Mahoney, System Admin
ikesheds here). My question is: Is it possible to do in such a way that keys would be backward-compatible? (I have no idea about the internal format of a PGP key, to me it's just bricktext...at least right now). -Dan -- "If you aren't going to try something, then we might as wel

Using gpg2 without pinentry?

2010-06-27 Thread Dan Mahoney, System Admin
re I sit.) Is there some reasonable way that gpg can detect that it has a controlling termainal (or even, a config file option) and just ask me for my passphrase on stdin? I am my sysadmin. I trust me :) -Dan -- "Let me tell you something about regrowing your dead wife Lucy, Harry. I

Re: Searching multiple keyservers

2010-06-23 Thread Dan Mahoney, System Admin
useful to specify servers you know don't synchronise reliably, when posting revocations. Considering I'm running on a FreeBSD system, however... -Dan -- "It would be bad." -Egon Spengler, "Ghostbusters" Dan Mahoney Techie, Sysadmin, WebGeek

Searching multiple keyservers

2010-06-23 Thread Dan Mahoney, System Admin
Hey all, Is there an easy syntax to chain multiple keyservers for searching? In theory it shouldn't be necessary, but there are distinct keyserver networks out there that don't share, as well as "private" hkp keyservers which might need to be searched first. -Dan -

Re: Using the "clean" function (and the "PGP Global Directory")

2010-06-22 Thread Dan Mahoney, System Admin
On Tue, 22 Jun 2010, Dan Mahoney, System Admin wrote: On Tue, 22 Jun 2010, David Shaw wrote: On Jun 22, 2010, at 11:02 PM, Dan Mahoney, System Admin wrote: It seems there's two interesting problems which inter-relate. The first is PGP corporation's "global directory&q

Re: Using the "clean" function (and the "PGP Global Directory")

2010-06-22 Thread Dan Mahoney, System Admin
On Tue, 22 Jun 2010, David Shaw wrote: On Jun 22, 2010, at 11:02 PM, Dan Mahoney, System Admin wrote: It seems there's two interesting problems which inter-relate. The first is PGP corporation's "global directory", which seems to operate orthogonally from every other

Using the "clean" function (and the "PGP Global Directory")

2010-06-22 Thread Dan Mahoney, System Admin
. Finally, it will sign your non-photo-uids. With a very short signature time, and pollute them so they look like this: uid Dan Mahoney sig 3E919EC51 2008-11-22 Dan Mahoney sig 3E8048D08 2009-10-15 Peter Losher sig 68D482E2 2009-08-31 Guy Sisalli s

Re: IDEA Status?

2010-06-22 Thread Dan Mahoney, System Admin
On Tue, 22 Jun 2010, Robert J. Hansen wrote: On 6/22/10 10:09 PM, Dan Mahoney, System Admin wrote: Is this very old and it's now supported? Or is it still not in for some other reason (either oversight, legal, or other). By modern standards, IDEA is not considered a promising cipher.

IDEA Status?

2010-06-22 Thread Dan Mahoney, System Admin
g/documentation/faqs.en.html#q3.3) Is this very old and it's now supported? Or is it still not in for some other reason (either oversight, legal, or other). - -Dan - -- - Dan Mahoney Techie, Sysadmin, WebGeek Gushi on efnet/undernet IRC ICQ: 13735144 AIM

Re: ...key belongs to ...

2010-05-29 Thread Dan Mahoney, System Admin
. -Dan -- "Don't be so depressed dear." "I have no endorphins, what am I supposed to do?" -DM and SK, February 10th, 1999 Dan Mahoney Techie, Sysadmin, WebGeek Gushi on efnet/undernet IRC ICQ: 13735144 AIM: LarpGM Si

Re: new Installation... configure issues

2010-05-24 Thread Dan Mahoney, System Admin
= 127 configure:3596: checking for C compiler default output file name It seems, I need to install C compiler by installing SPROcc 9(unbundled SPARCworks Professional C compiler) Please advise on this. Thanks, Raj You could just install gcc. -Dan -- "Blargy Frap!" -mtreal, ef

Symantec buys PGP and Guardian Edge

2010-04-29 Thread dan
By Jeremy Kirk, IDG News Service http://www.pcworld.com/businesscenter/article/195217/symantec_buys_encryption_specialist_pgp_for_300m.html Symantec will acquire encryption specialist PGP and endpoint security vendor GuardianEdge Technologies for US$300 million and $70 million respectively, the

Re: Implications Of The Recent RSA Vulnerability

2010-03-11 Thread Dan Mahoney, System Admin
: Researchers who had physical enough access to be able to rewire the private-key-holder's system's power supply were able to compromise that system. If you're at that point, I don't think key length is your problem. -Dan Mahoney -- Dan Mahoney Techie, Sysadmi

Re: Continued PKA problems on Windows

2010-03-03 Thread Dan Mahoney, System Admin
02 redirects before you actually get to the file. It wouldn't be totally unsurprising to me if a series of redirects caused problems. So, if you're interested in comparing apples to apples, for curiosity I just uploaded your pubkey (sean.pubkey.txt) to the same url as danm.pubkey.txt)

  1   2   >