Re: In case you use OpenPGP on a smartphone ...

2020-08-11 Thread Philihp Busby via Gnupg-users
On 2020-08-11T21:18:24+0200 Johan Wevers wrote 0.9K bytes: > On 11-08-2020 17:18, Stefan Claas wrote: > > >> Why hardware? If a bug is found you can't upgrade it easily. > > > > Because hardware can't be tampered with like software. > > If a hardware bug is found you're still lost. Even

Re: Why does gpg -k write to tofu.db?

2020-08-11 Thread Brian Minton
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Tue, Aug 11, 2020 at 5:32 PM Brian Minton wrote: > > I have a lot of public keys in my keybox (it's about 45 MB or so). > I was trying to figure out why seemingly innocent tasks in gpg take > a very long time. It seems that gnupg is making a

Re: Why does gpg -k write to tofu.db?

2020-08-11 Thread Brian Minton
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Tue, Aug 11, 2020 at 5:32 PM Brian Minton wrote: > > I have a lot of public keys in my keybox (it's about 45 MB or so). > I was trying to figure out why seemingly innocent tasks in gpg take > a very long time. It seems that gnupg is making a

Re: In case you use OpenPGP on a smartphone ...

2020-08-11 Thread Stefan Claas
ved...@nym.hush.com wrote: > There is already a simple existing solution. > > [1] Encrypt and decrypt on a computer that has internet hardware disabled. > > [2] Use an Orbic Journey V phone that gets and sends *only text* > > [3] Use a microsd expansion card on the orbis phone > > [4] set

Why does gpg -k write to tofu.db?

2020-08-11 Thread Brian Minton via Gnupg-users
I have a lot of public keys in my keybox (it's about 45 MB or so). I was trying to figure out why seemingly innocent tasks in gpg take a very long time. It seems that gnupg is making a very long running transaction to the sqlite3 database ~/.gnupg/tofu.db laptop:~/.gnupg$ date;ls -last Tue 11

Re: In case you use OpenPGP on a smartphone ...

2020-08-11 Thread Stefan Claas
ಚಿರಾಗ್ ನಟರಾಜ್ via Gnupg-users wrote: > Yubikey dealt with a mass recall only last year due to a bug in their > firmware: > https://www.engadget.com/2019-06-13-yubico-recalls-government-grade-security-keys-due-to-bug.html Quote: Fortunately, any affected customers will receive a replacement

Re: In case you use OpenPGP on a smartphone ...

2020-08-11 Thread Johan Wevers
On 11-08-2020 21:49, vedaal via Gnupg-users wrote: > There is already a simple existing solution. Simple is not how I see this. > [1] Encrypt and decrypt on a computer that has internet hardware disabled. > [2] Use an Orbic Journey V phone that gets and sends *only text* > [3] Use a microsd

Re: In case you use OpenPGP on a smartphone ...

2020-08-11 Thread ಚಿರಾಗ್ ನಟರಾಜ್ via Gnupg-users
Yubikey dealt with a mass recall only last year due to a bug in their firmware: https://www.engadget.com/2019-06-13-yubico-recalls-government-grade-security-keys-due-to-bug.html -- ಚಿರಾಗ್ ನಟರಾಜ್ Pronouns: he/him/his 11/08/20 22:10 ನಲ್ಲಿ, Stefan Claas ಬರೆದರು: > > Johan Wevers wrote: > > > On

Re: In case you use OpenPGP on a smartphone ...

2020-08-11 Thread Stefan Claas
Johan Wevers wrote: > On 11-08-2020 17:18, Stefan Claas wrote: > > >> Why hardware? If a bug is found you can't upgrade it easily. > > > > Because hardware can't be tampered with like software. > > If a hardware bug is found you're still lost. Even Apple has found out > the hard way. Yes,

Re: In case you use OpenPGP on a smartphone ...

2020-08-11 Thread vedaal via Gnupg-users
On 8/11/2020 at 3:00 PM, "Stefan Claas" wrote: ... >As understood a Pegasus operator can do what ever >he likes to do remotely, anonymously with our (Android/iOS) >smartphone, without that we know that this happens. ... >in form of a best practice FAQ (cross-platform), to no longer use

Re: In case you use OpenPGP on a smartphone ...

2020-08-11 Thread Johan Wevers
On 11-08-2020 17:18, Stefan Claas wrote: >> Why hardware? If a bug is found you can't upgrade it easily. > > Because hardware can't be tampered with like software. If a hardware bug is found you're still lost. Even Apple has found out the hard way. >> On mobile, encrypted messengers are the

Re: In case you use OpenPGP on a smartphone ...

2020-08-11 Thread ಚಿರಾಗ್ ನಟರಾಜ್ via Gnupg-users
I suppose, you're right. I'm wary of blindly believing videos, especially when faking them has become relatively easy at this point. I think one thing both Android and iOS get wrong is that the user isn't really in control of the device. So many manufacturer ROMs have built-in bloatware and

Re: In case you use OpenPGP on a smartphone ...

2020-08-11 Thread Stefan Claas
Andrew Gallagher wrote: > It matters little whether these statements were made by Snowden. Whether a > particular piece of software exists or not, and > whether it is owned by the Russians or the Israelis or the Americans, is > beside the point. In principle, it can exist and > similar pieces

Re: In case you use OpenPGP on a smartphone ...

2020-08-11 Thread Andrew Gallagher
It matters little whether these statements were made by Snowden. Whether a particular piece of software exists or not, and whether it is owned by the Russians or the Israelis or the Americans, is beside the point. In principle, it can exist and similar pieces of software have existed in the

Re: In case you use OpenPGP on a smartphone ...

2020-08-11 Thread Stefan Claas
ಚಿರಾಗ್ ನಟರಾಜ್ via Gnupg-users wrote: > > 11/08/20 17:18 ನಲ್ಲಿ, Stefan Claas ಬರೆದರು: > > > > And you think that continuing with those is a good practice since > > Mr Snowden's YouTube Video was released? > > I mean, don't you think it's odd that you can't find a single other source > for

Re: In case you use OpenPGP on a smartphone ...

2020-08-11 Thread ಚಿರಾಗ್ ನಟರಾಜ್ via Gnupg-users
11/08/20 17:18 ನಲ್ಲಿ, Stefan Claas ಬರೆದರು: > > And you think that continuing with those is a good practice since > Mr Snowden's YouTube Video was released? I mean, don't you think it's odd that you can't find a single other source for those statements coming from Snowden? And don't you find

Re: In case you use OpenPGP on a smartphone ...

2020-08-11 Thread Stefan Claas
Johan Wevers wrote: > On 11-08-2020 11:39, Stefan Claas wrote: > > > Based on my proposal, I would like to see in the future (OpenSource) > > *hardware* based encryption products, for at least voice comms, which > > is affordable for the majority of us and easy to use, so that people > > do not

Re: In case you use OpenPGP on a smartphone ...

2020-08-11 Thread Johan Wevers
On 11-08-2020 11:39, Stefan Claas wrote: > Based on my proposal, I would like to see in the future (OpenSource) > *hardware* based encryption products, for at least voice comms, which > is affordable for the majority of us and easy to use, so that people > do not need to use good old email

Re: In case you use OpenPGP on a smartphone ...

2020-08-11 Thread Stefan Claas
Mark wrote: > I was thinking about getting an app called iPGMail for iPhone/iPad to > use PGP on them. From my very limited experience it looks like it might > be a good choice as well. For me it looks like that encryption alà OpenPGP, whether iOS or Android is unfortunately dead, after I have

Re: In case you use OpenPGP on a smartphone ...

2020-08-11 Thread Stefan Claas
Matthias Apitz wrote: > El día Montag, August 10, 2020 a las 09:07:51 +0200, Stefan Claas escribió: > > > > One can use a Linux mobile phone running UBports.com (as I and all my > > > family do) > > > or the upcoming Puri.sm L5 (as I pre-ordered in October 2017). > > > > Yes, people gave me

Re: In case you use OpenPGP on a smartphone ...

2020-08-11 Thread Matthias Apitz
El día Montag, August 10, 2020 a las 09:07:51 +0200, Stefan Claas escribió: > > One can use a Linux mobile phone running UBports.com (as I and all my > > family do) > > or the upcoming Puri.sm L5 (as I pre-ordered in October 2017). > > Yes, people gave me already (not from here of course) good