From: lcottrell@popmail.ucsd.edu (Lance Cottrell)
To: cypherpunks@toad.com
Message Hash: 61d12246e3e744258681849f94a41f5d7d82f94e360df508fe5f9f754a0864dc
Message ID: <199407012234.PAA09853@ucsd.edu>
Reply To: N/A
UTC Datetime: 1994-07-01 22:37:50 UTC
Raw Date: Fri, 1 Jul 94 15:37:50 PDT
From: lcottrell@popmail.ucsd.edu (Lance Cottrell)
Date: Fri, 1 Jul 94 15:37:50 PDT
To: cypherpunks@toad.com
Subject: Re: Physical storage of key is the weakest link
Message-ID: <199407012234.PAA09853@ucsd.edu>
MIME-Version: 1.0
Content-Type: text/plain
tcmay@netcom.com tells us:
>Much more likely:
>
>* Diskettes left lying around. Secret keys on home computers.
>
>* Incompletely erased files. (Norton Utilities can recover erased
>files; mil-grade multiple-pass erasure may be needed.)
>
>
>A simple search warrant executed on your premises will usually crack
>open all your crypto secrets. (Fixes to this are left as an exercise.)
>
>Where to store one's secret key is an issue that makes academic the
>issue of whether one's key can be compelled. A diskette stored at
>one's home, in one's briefcase, etc., can be gotten. A pendant or
>dongle or whatever that stores the key can also be gotten. The
>passphrase (8-12 characters, typically) is secure, but not the key.
>
>--Tim May
If your passphrase is good (128+ bits of entropy), then your private key is
as secure as the messages that you send. Although it need be broaken only
once, I see no real danger of IDEA being compromised in the near future.
Given a good passphrase, I would suggest that you want multiple coppies of
your key to prevent loss or accidental destruction. My passphrase is > 30
characters. Fortunately Mac PGP remembers the key during any given session
so typing is kept down a bit.
--------------------------------------------------
Lance Cottrell who does not speak for CASS/UCSD
loki@nately.ucsd.edu
PGP 2.3 key available by finger or server.
"Love is a snowmobile racing across the tundra. Suddenly
it flips over, pinning you underneath. At night the ice
weasels come."
--Nietzsche
Return to July 1994
Return to “lcottrell@popmail.ucsd.edu (Lance Cottrell)”
1994-07-01 (Fri, 1 Jul 94 15:37:50 PDT) - Re: Physical storage of key is the weakest link - lcottrell@popmail.ucsd.edu (Lance Cottrell)