Hi, not using chmod -t just makes your encrypted secstore available to offline brute-force attacks. if you keep it only in your ephemeral disc (fossil in my system) rather than the WORM disk (or psudo-worm these days) (i use venti) it it a little less vulnerable.
its marginal, i agree, but a little more safety is always a good thing. the downside is you have to be responsible for your own backup (hence the thumb drive). -Steve > On 5 Oct 2026, at 4:46 pm, requiem. via 9fans <[email protected]> wrote: > > On Fri, 2 Oct 2026 09:46:05 +0100 > Steve Simon <[email protected]> wrote: > >> there is a script ipso(1) which wraps up the operations you need to >> manage factotum keys, and it supports secstore, and using an >> encrypted local file. > > thank you! i tried poking at `ipso` in the past but because i couldn't > get the secstore working i always failed -- finally it seems to work, > so i can actually learn using this now! thank you for the reminder. > >> NB: you might want to chmod -t your lical file to prevent it going >> into your disc archive (venti/getfs/cwfs etc). though putting a!copy >> (encrypted) on a thumb drive every so often is a good policy. > > could you explain why it going into the disc archive would present a > problem? > ------------------------------------------ 9fans: 9fans Permalink: https://9fans.topicbox.com/groups/9fans/Tcf9c4dd764d4b456-Md194c5f30b4bd859a3733c16 Delivery options: https://9fans.topicbox.com/groups/9fans/subscription
