Re: OpenPGP Smartcard Advantages

2005-06-03 Thread Alex L. Mauer
Jan Niehusmann wrote: I wondered if the card couldn't just erase itself completly when the wrong Admin-PIN is entered three times. This would at least save the card itself, which is worth some euros. But OTOH, just locking the card is probably easier to implement in a safe way (it's an atomic op

Re: OpenPGP Smartcard Advantages

2005-06-03 Thread Jan Niehusmann
On Fri, Jun 03, 2005 at 09:30:22AM -0500, Alex L. Mauer wrote: > Wouldn't it thus be trivial [for a malicious host] to destroy a smart > card (by sending the wrong admin pin repeatedly)? It is - but a malicious card reader could also fry the card with some high voltage pulses. But at least you kno

Re: OpenPGP Smartcard Advantages

2005-06-03 Thread Alex L. Mauer
Werner Koch wrote: The only thing a malicious host can do is to lock the card (by sending several times a wrong PIN) and to trick you into signing or decrypting data. This just made me think. Wouldn't it thus be trivial [for a malicious host] to destroy a smart card (by sending the wrong admi

Re: OpenPGP Smartcard Advantages

2005-04-13 Thread Mark H. Wood
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 That reminds me: would someone please point me to a thorough discussion of why I should be able to trust a smartcard, given that an untrusted computer has complete control of the channel between me and my card. - -- Mark H. Wood, Lead System Program

Re: OpenPGP Smartcard Advantages

2005-04-12 Thread David
On Tue, Apr 12, 2005 at 09:47:40AM +0200, Werner Koch wrote: > Signing and decrypting is done inside the card. > > The only thing a malicious host can do is to lock the card (by sending > several times a wrong PIN) and to trick you into signing or decrypting > data. > > > Salam-Shalom, > >W

Re: OpenPGP Smartcard Advantages

2005-04-12 Thread Werner Koch
On Mon, 11 Apr 2005 10:08:10 -0700, David said: > 1. What are the advantages of this smartcard for storing my keys over > other external media (especially if connected to an unsafe computer)? Without physical access to the card it is not possible to extract the keys. With physical access it is

OpenPGP Smartcard Advantages

2005-04-11 Thread David
Hello, I am new to smartcards and I have a couple of questions about the OpenPGP smartcard from www.g10code.de 1. What are the advantages of this smartcard for storing my keys over other external media (especially if connected to an unsafe computer)? 2. Is the signing / encrypting done inside th