Some general security questions

2013-09-08 Thread Petrus

I got the subject of the message I just sent wrong.
My apologies; it was intended to be some general
questions.  I simply hit reply to thread, as a means
of automatically providing the address in the send
field.  If possible, please disregard it from the xfs still in heir 
thread.


Greetings,

I have some security-related questions; admittedly of a rather elemental
nature.  I hope that is not a problem.

The first question I wanted to ask, is what is the opinion of people on
this list, concerning an ideal umask for general use?  I have not
changed the root umask on my own system, but for my own use, after some
research on the Web and my own thinking, changed the umask of my
unpriveleged account to 077.  Do people here actually consider that too
extreme, or is it appropriate?

I also wanted to ask people here, for information about the preferred
configuration of sudo.  After again attempting to investigate on the
Web, my own sudo configuration currently has four credentials; username,
unique (non-wheel) group name, machine address, and password.  Is that
a reasonably secure setup, or is there something more than that, which
some of you usually do?

My third question is a little more sensitive.  I have read about claims
in the media recently that there may not be any form of cryptography in
existence which is unbreakable by...certain parties.  Given that I am
less than a novice in the subject myself, I wanted to ask if there were
any particularly robust algorithms that could be recommended for
keeping certain files private.

My thanks.



Re: Some general security questions

2013-09-08 Thread Martin Schröder
2013/9/8 Petrus petr...@gmail.com:
 My third question is a little more sensitive.  I have read about claims
 in the media recently that there may not be any form of cryptography in
 existence which is unbreakable by...certain parties.  Given that I am
 less than a novice in the subject myself, I wanted to ask if there were
 any particularly robust algorithms that could be recommended for
 keeping certain files private.

https://www.schneier.com/blog/archives/2013/09/the_nsa_is_brea.html

Best
   Martin



Re: Some general security questions

2013-09-08 Thread Alexander Hall
Petrus petr...@gmail.com wrote:
I got the subject of the message I just sent wrong.
My apologies; it was intended to be some general
questions.  I simply hit reply to thread, as a means
of automatically providing the address in the send
field.

Please don't. You implicitely add various reference headers fucking up 
threading. Using thunderbird, you might have noticed.

/Alexander