output of --check-trustdb

2012-08-18 Thread Hauke Laging
Hello, I am trying to understand how the trust calculations work and I think I have made serious progress in that... ;-) There are at least two things I have not understood yet: 1) Is it possible to have the ownertrust value shown with --list-keys? Validity can be shown. I had expected a paramet

check-passphrase-pattern

2012-08-18 Thread Faramir
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hello, I saw a message at spanish help list, requesting where to find an example pattern file to use with check-passphrase-pattern option. Since this list is a lot more populated than spanish list, I thought I should forward the question here.

Re: how vulnerable is "hidden-encrypt-to"

2012-08-18 Thread Hauke Laging
Am Sa 18.08.2012, 10:36:21 schrieb Daniel Kahn Gillmor: > It's worth observing that you can still detect the algorithm used and > the size of the key, even when the keyid is all zeros. So if someone > has a particularly unusual key size (or is an early adopter of an > unusual key type, like ECC),

Re: how vulnerable is "hidden-encrypt-to"

2012-08-18 Thread Daniel Kahn Gillmor
On 08/17/2012 11:16 AM, Hauke Laging wrote: > Am Fr 17.08.2012, 09:56:56 schrieb auto15963931: >> or what key ID >> had been used in conjunction with that option? Thanks. > > You need the private recipient key in order to find out that key ID. It's the > use of this option that you cannot get thi

Re: OpenPGP smartcard, how vulnerable is it?

2012-08-18 Thread Peter Lebbing
On 16/08/12 10:29, gn...@lists.grepular.com wrote: > It can attempt to initiate decryption/signing, but it still requires the > user to enter their pin, so some sort of social engineering is also > required. It could wait for you to try to decrypt/sign something, and then > send some alternative da