Re: Have I caught a firmware attack in the act? Or am I just paranoid?

2019-08-23 Thread Elmar Stellnberger
The key question about it is how the archive keys are handled. I believe that keeping such a key offline would be a whole lot of work. It would perhaps also help to have it on a gpg-Smartcard. Am 23.08.19 um 09:10 schrieb Rebecca N. Palmer: On 17/08/2019 12:18, Elmar Stellnberger wrote: to

Re: Have I caught a firmware attack in the act? Or am I just paranoid?

2019-08-23 Thread Rebecca N. Palmer
On 17/08/2019 12:18, Elmar Stellnberger wrote: to be safe the key handling policy needs to be offline enforced There have been various attempts to encourage / simplify the use of offline keys, but it isn't currently required in Debian, and some of them only suggest keeping the master key