Update

2009-02-11 Thread Robert J. Hansen
Regarding the shredded CD-R: I talked to my source and reminded him of our 2005 conversation. It became clear that further details are not available for public release. In light of this, I have to withdraw my statement. I can't back it up; and that means regardless of whether it's true or false,

Re: where to start?

2009-02-11 Thread Robert J. Hansen
Faramir wrote: > Well, as Robert J. Hansen already said Please -- just Rob. I go by "Robert J. Hansen" professionally, to reduce confusion with some other people in the security community who are named Robert Hansen. But everybody just calls me Rob. > But if you use FireGPG, beware of auto savi

Re: where to start?

2009-02-11 Thread Faramir
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Dr. Scott S. Jones escribió: > I run both Win xp and ubuntu 8.10. My wife runs win xp on her laptop. We are > at the point now where we both want to enable encrypted emailing AND we want > to find a nice way of educating those we email to often, or w

Re: Hibernation and secret keys

2009-02-11 Thread Ingo Klöcker
On Wednesday 11 February 2009, David Shaw wrote: > On Wed, Feb 11, 2009 at 10:37:43PM +0100, Ingo Kl?cker wrote: > > On Wednesday 11 February 2009, David Shaw wrote: > > > On Wed, Feb 11, 2009 at 12:59:48PM +0100, Christoph Anton > > > Mitterer > > > > wrote: > > > > A good workaround is to use dis

Re: Hibernation and secret keys

2009-02-11 Thread Ingo Klöcker
On Wednesday 11 February 2009, Christoph Anton Mitterer wrote: > On Wed, 2009-02-11 at 22:37 +0100, Ingo Klöcker wrote: > > > Your machine suspends, and writes a snapshot of its memory to > > > disk. Sure, let's say it's even encrypted. When you wake the > > > machine, is the encrypted disk still

decryption failed: secret key not available

2009-02-11 Thread Collings, David H.
Hello, I've seen similar issues in some other posts, but still am unclear as to how to resolve my issue. I am trying to run a script to decrypt a file automatically from our job scheduler (UC4). I am able to run the script from the command prompt or by executing the .bat file from the server.

Re: Howto import more than one key from a keyserver at a time

2009-02-11 Thread David Shaw
On Tue, Feb 10, 2009 at 11:29:15AM -0600, John Clizbe wrote: > It won't check the keys that it needs to fetch, you'll need to run > the commands again. Note, this can get you a LOT of keys that you > may have little interest in. Indeed, a whole lot of keys. It might be more useful to pick a pers

Re: Hibernation and secret keys

2009-02-11 Thread Christoph Anton Mitterer
On Wed, 2009-02-11 at 17:00 -0500, David Shaw wrote: > If the answer is "Yes", then you're not protecting very much. You did > not succeed in doing what you were trying to do. If the answer is > "No", you at least avoided the usual pitfalls. Yep,... you're right =) It should be really possibly t

Re: Hibernation and secret keys

2009-02-11 Thread David Shaw
On Wed, Feb 11, 2009 at 10:37:43PM +0100, Ingo Kl?cker wrote: > On Wednesday 11 February 2009, David Shaw wrote: > > On Wed, Feb 11, 2009 at 12:59:48PM +0100, Christoph Anton Mitterer > wrote: > > > A good workaround is to use disk encryption (dm-crypt or similar > > > things). > > > > Encrypted d

Re: Hibernation and secret keys

2009-02-11 Thread Christoph Anton Mitterer
On Wed, 2009-02-11 at 22:37 +0100, Ingo Klöcker wrote: > > Your machine suspends, and writes a snapshot of its memory to disk. > > Sure, let's say it's even encrypted. When you wake the machine, is > > the encrypted disk still mounted? > > Obviously not. Why? This IS of course possible... Of c

Re: Hibernation and secret keys

2009-02-11 Thread Ingo Klöcker
On Wednesday 11 February 2009, David Shaw wrote: > On Wed, Feb 11, 2009 at 12:59:48PM +0100, Christoph Anton Mitterer wrote: > > A good workaround is to use disk encryption (dm-crypt or similar > > things). > > Encrypted disks don't help without serious OS support around suspend. Obviously. > Y

Importing RSA Private Keys into GPG 2.0.10

2009-02-11 Thread Andrew Robinson
I'm trying to find a method to import an RSA Private Key into GPG, i've already god a generated RSA Private Key but when ever I try the import I get: gpg: no valid OpenPGP data found. gpg: Total number processed: 0 Which makes sense as it's not OpenPGP data thats in the file! Is there any

Re: Hibernation and secret keys

2009-02-11 Thread David Shaw
On Wed, Feb 11, 2009 at 12:59:48PM +0100, Christoph Anton Mitterer wrote: > A good workaround is to use disk encryption (dm-crypt or similar things). Encrypted disks don't help without serious OS support around suspend. Your machine suspends, and writes a snapshot of its memory to disk. Sure, let'

Re: where to start?

2009-02-11 Thread Ingo Klöcker
On Wednesday 11 February 2009, Robert J. Hansen wrote: > Dr. Scott S. Jones wrote: > > I run both Win xp and ubuntu 8.10. My wife runs win xp on her > > laptop. We are at the point now where we both want to enable > > encrypted emailing AND we want to find a nice way of educating > > those we email

Re: Are GNUPG Keyservers ordinary LDAP Servers?

2009-02-11 Thread David Shaw
On Feb 11, 2009, at 10:10 AM, 小波 顾 wrote: From: guxiaobo1...@hotmail.com To: gnupg-us...@gnu.org Subject: Are GNUPG Keyservers ordinary LDAP Servers? Some of them are, yes. Some of them are SKS: http://www.nongnu.org/sks/ GPG speaks several keyserver protocols, including LDAP, HKP (what SKS

Are GNUPG Keyservers ordinary LDAP Servers?

2009-02-11 Thread 小波 顾
From: guxiaobo1...@hotmail.comto: gnupg-us...@gnu.orgsubject: Are GNUPG Keyservers ordinary LDAP Servers?Date: Wed, 11 Feb 2009 23:09:22 +0800 What can you do with the new Windows Live? Find out _ Invite your mail contacts to jo

Re: paperkey // ? feature request

2009-02-11 Thread David Shaw
On Feb 11, 2009, at 3:00 AM, Benjamin Donnachie wrote: This thread reminded me of the attached... Even more amusing (and accurate) is the ALT text you can see when you mouse over the picture. David ___ Gnupg-users ma

Re: OpenPGP card not accessible; ctapi-driver option in gpg.conf does the job for me (with cyberjack reader)

2009-02-11 Thread pheaneas
Hi there, I hope I can forward an argument for not dropping (direct?) support for CT/API readers in GnuPG too soon, as Werner often states (and as the ctapi-driver option is also marked as deprecated in the gpg man page). Quite recently I dug out my old OpenPGP card again, which I had bought in

Using a smart card with revoked keys

2009-02-11 Thread Enrico Zini
Hello, some time ago I lost my card reader, so I revoked the keys on the smart card because I wouldn't have been able to use them for quite some time, until I got a new one. Now I managed to get a new card reader, and I discovered that gpg doesn't want to use those subkeys: if I try to decode som

gnupg on celeron and atom cpus

2009-02-11 Thread Christoph Anton Mitterer
Hi. Does anyone of you have an idea whether it could make problems to use gnupg on Celeron or Atom CPUs? I mean could this have an effect on the PRNG, e.g. that the entropy is worse? Or something similar? Regards, Chris. smime.p7s Description: S/MIME cryptographic signature __

Copy subkeys to primary key

2009-02-11 Thread Ian Hill
For whatever reason I now have two versions of my private key one without the ELG encryption key and primary key, the other without the RSA signing key. How can I combine them so I have one secret key with both the ELG and RSA subkeys under the primary key. This is my new key sec# 1024D/BE7E87F

Re: Hibernation and secret keys

2009-02-11 Thread Christoph Anton Mitterer
A good workaround is to use disk encryption (dm-crypt or similar things). Best wishes, Chris. smime.p7s Description: S/MIME cryptographic signature ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users

Re: Hibernation and secret keys

2009-02-11 Thread Werner Koch
On Wed, 11 Feb 2009 02:17, ds...@jabberwocky.com said: > GPG does have some countermeasures against this sort of thing, but > given the nature of the problem, they are far from infallible. For example you can send a HUP to gpg-agent from a suspend event script. This makes sure that gpg-agent clea

Re: paperkey // ? feature request

2009-02-11 Thread Faramir
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Benjamin Donnachie escribió: > This thread reminded me of the attached... LOL, right... but it could be even worst... a few drops of Scopolamine (prepared as Burundanga) in your beer, and the attacker would be able to make you tell him your passph

Re: paperkey // ? feature request

2009-02-11 Thread Benjamin Donnachie
This thread reminded me of the attached... Ben <>___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users