Re: gpg keys on USB drive





On Fri, Jun 17, 2011 at 09:23:43PM -0400, Robert Simmons wrote:
I have been reading up on keeping encryption secret keys on a USB thumb drive
so that there is an "air gap" so to speak except when the drive is inserted in
the machine and mounted.

Is it possible to replace all the files in my home directory with symbolic
links to the corresponding files in the USB drive? This seems easy, but how
can I be sure in FreeBSD that the symlinks will always work when the drive is
plugged in? I have noticed that the device is sometimes different depending on
what other USB devices are plugged in and where they are plugged in.

Also, other than the obvious drawback of needing to remember where the drive
is, and plug it in, are there any drawbacks to keeping keysets such as for
OpenSSH, geli providers, GnuPG, KWallet, and BitCoin on a USB drive?

Lastly, using geli to create a passphrase based encrypted provider ON the USB
drive before storing everything on there would increase its security, no?

Checkout /etc/devd.conf where you can match that USB device specifically
with some entries and fire a script to perform whatever ``action''
neccesary to achieve the conditions that you have to meet. There should
be sufficient examples in that file already that would give you a head
start & clue of what to add.

This might not be your best choice if your not comfortable with
scripting though.

Attachment: pgpuEYtBZeb1T.pgp
Description: PGP signature



Relevant Pages

  • RE: Controlling specific USB devices on Windows XP
    ... Controlling specific USB devices on Windows XP ...
    (Focus-Microsoft)
  • RE: USB Device Not Recognized - If u can solve this one, you are truly
    ... I have a computer that gives the following error when I plug in some USB ... Windows does not recognize it. ... |- Unused Port ... I've removed all USB devices from device ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: External USB Drive not detected
    ... "USB device recognized. ... One of the USB devices attached to the computer ... I then plugged a regular 2G memory stick into the same port, ... port without having to rely on your Windows installation. ...
    (microsoft.public.windowsxp.general)
  • RE: USB Device Not Recognized - If u can solve this one, you are truly
    ... Everyone who has a SanDisc please call 1-866-248-4498. ... I have a computer that gives the following error when I plug in some USB ... Jump Drives: 'USB Device Not Recognized'. ... I've removed all USB devices from device ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: USB error message
    ... > USB devices attached to this computer as yet. ... two USB flash drives and you know both of those drives are non-defective & ... > I have uninstalled the USB devices and reloaded them to no avail. ... installation worked without problems, yes? ...
    (microsoft.public.windowsxp.help_and_support)