Re: Crowdfunding USB Security Key for Email- and Data-Encryption - Nitrokey Storage

2015-11-21 Thread Jan Suhr
Hi Malte! Am 20.11.2015 11:26, schrieb Malte: > Hi, > > very nice! > > Two questions/remarks, though: > > On Thursday 19 November 2015 22:37 Jan Suhr wrote: >> The firmware and hardware of Nitrokey Storage have already been >> verified >> by Cure59, a professional third-party security auditor.

Re: Crowdfunding USB Security Key for Email- and Data-Encryption - Nitrokey Storage

2015-11-21 Thread Peter Lebbing
On 21/11/15 09:00, Jan Suhr wrote: > All serious findings are fixed already. Look for the "Note" at the end > of each issue description. I suppose by "serious" you mean "defined as 'Critical' in the pentest"? There are unfixed issues with severity "High": Firmware: NK-01-008 OTP can be unlocked b

Re: backing up keys

2015-11-21 Thread Peter Lebbing
On 17/11/15 15:53, Andrew Gallagher wrote: > No, there is no public key data embedded in the private key, but you can > regenerate the important mathematical bits of the public key from the > private key, and you can fill in your name, email etc. from memory. So > it's not absolutely necessary - bu

AW: scdaemon lockup with Yubikey NEO

2015-11-21 Thread the2nd
Hi Ben, We have a similar Problem since we've upgraded from Ubuntu 15.04 to 15.10.   When starting gpg-agent with --log-file the log show the following: 2015-05-30 13:49:36 gpg-agent[3600] error accessing card: Conflicting use 2015-05-30 13:49:36 gpg-agent[3600] smartcard signing failed:  Conflic

Re: backing up keys

2015-11-21 Thread Peter Lebbing
On 21/11/15 13:09, Peter Lebbing wrote: > GnuPG outputs both a "Secret-Key Packet" as well as all UID's and > binding signatures. It might output all certifications by others on the > key as well; I'm going to write a separate mail about this. Okay, it turns out it was a weird issue with my keyrin

Re: Crowdfunding USB Security Key for Email- and Data-Encryption - Nitrokey Storage

2015-11-21 Thread NdK
Il 21/11/2015 12:07, Peter Lebbing ha scritto: > Personally, I don't really see yet why the latter is so important; > however, gaining the ability to issue OTP's by simply inserting my own > OpenPGP card with my own PIN seems serious? Do I misunderstand it? Or is > it not part of the threat model

Re: scdaemon lockup with Yubikey NEO

2015-11-21 Thread Lance R. Vick
This happens to me constantly as well. I my case I frequently need to kill and restart gpg-agent to get things working again on both Arch Linux and Gentoo. On Sat, Nov 21, 2015 at 4:41 AM, the2nd wrote: > Hi Ben, > > We have a similar Problem since we've upgraded from Ubuntu 15.04 to > 15.10. W