Best practices for securely creating master RSA key

2014-05-10 Thread Tomer Altman
To whom it may concern, I recall reading somewhere some best practices for creating one's initial RSA key pair that they intend for building their Web of Trust. I think the recommended steps were: 1. Find a computer that you think is relatively free of malware 2. Download a Live Linux distro

Re: Best practices for securely creating master RSA key

2014-05-10 Thread Ingo Klöcker
On Saturday 10 May 2014 01:23:57 Tomer Altman wrote: To whom it may concern, I recall reading somewhere some best practices for creating one's initial RSA key pair that they intend for building their Web of Trust. I think the recommended steps were: 1. Find a computer that you think is

Re: a bit OT: pgpdump binaries?

2014-05-10 Thread Ben McGinnes
On 9/05/14 6:34 PM, Josef Schneider wrote: Hi, something strange happened in my mail client so the signature of the last message was invalid! I'm sure we've all had that happen at some point. Anyway, thanks, I'm sure Faramir will appreciate these and I can probably think of a few other

Re: Best practices for securely creating master RSA key

2014-05-10 Thread Daniel Kahn Gillmor
Hi Tomer-- On 05/10/2014 05:23 AM, Tomer Altman wrote: 1. Find a computer that you think is relatively free of malware 2. Download a Live Linux distro CD/DVD/USB, and verify its signatures to make sure you are not installing a tainted version 3. Launch the verified Linux distro. 4. Use