1 |
On 08/20/2018 10:18 PM, Alec Warner wrote: |
2 |
> Are there other ways to measure if the keys are used in the manner we are |
3 |
> hoping for? |
4 |
|
5 |
Nope... additional complexity arise if multiple signing keys exists |
6 |
(primary or subkeys), and furthermore there is no guarantee the key is |
7 |
stored on key only. |
8 |
|
9 |
That said, the actual security is even further muddied by operational |
10 |
security concerns regarding how the primary key is accessed even in the |
11 |
event signing subkey is on card only.. and other security precations |
12 |
required by the developers for the token to have any meaningful addition |
13 |
to security as an attacker can anyways just wait for it to be be |
14 |
available, in particular if not mandating forcesig on the openpgp applet |
15 |
and counting the number of signatures manually to detect abnormalities. |
16 |
|
17 |
I really would like to see a properly written up memorandum on the |
18 |
threat model this suggestion is intended to protect against and the |
19 |
cost/benefit analysis involved in the decision making; to me it sounds |
20 |
like some people think it is a panacea without much actual considerations. |
21 |
|
22 |
-- |
23 |
Kristian Fiskerstrand |
24 |
OpenPGP keyblock reachable at hkp://pool.sks-keyservers.net |
25 |
fpr:94CB AFDD 3034 5109 5618 35AA 0B7F 8B60 E3ED FAE3 |