Gentoo Archives: gentoo-nfp

From: Kristian Fiskerstrand <k_f@g.o>
To: gentoo-nfp@l.g.o, Alec Warner <antarus@g.o>
Subject: Re: [gentoo-nfp] Developer Crypto Hardware (AGM)
Date: Mon, 20 Aug 2018 20:27:56
Message-Id: fd11f51d-2c20-0b6e-c0dd-8bf2a6ce4493@gentoo.org
In Reply to: Re: [gentoo-nfp] Developer Crypto Hardware (AGM) by Alec Warner
1 On 08/20/2018 10:18 PM, Alec Warner wrote:
2 > Are there other ways to measure if the keys are used in the manner we are
3 > hoping for?
4
5 Nope... additional complexity arise if multiple signing keys exists
6 (primary or subkeys), and furthermore there is no guarantee the key is
7 stored on key only.
8
9 That said, the actual security is even further muddied by operational
10 security concerns regarding how the primary key is accessed even in the
11 event signing subkey is on card only.. and other security precations
12 required by the developers for the token to have any meaningful addition
13 to security as an attacker can anyways just wait for it to be be
14 available, in particular if not mandating forcesig on the openpgp applet
15 and counting the number of signatures manually to detect abnormalities.
16
17 I really would like to see a properly written up memorandum on the
18 threat model this suggestion is intended to protect against and the
19 cost/benefit analysis involved in the decision making; to me it sounds
20 like some people think it is a panacea without much actual considerations.
21
22 --
23 Kristian Fiskerstrand
24 OpenPGP keyblock reachable at hkp://pool.sks-keyservers.net
25 fpr:94CB AFDD 3034 5109 5618 35AA 0B7F 8B60 E3ED FAE3

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
Re: [gentoo-nfp] Developer Crypto Hardware (AGM) Alec Warner <antarus@g.o>