Re: 2 security issues

From: Seth Arnold (sarnold@wirex.com)
Date: 12/13/01


Date: Thu, 13 Dec 2001 13:30:59 -0800
From: Seth Arnold <sarnold@wirex.com>
To: Focus on Linux Mailing List <focus-linux@securityfocus.com>


On Wed, Dec 12, 2001 at 03:12:50PM -0500, mike ledoux wrote:
> > Just remember that anything that can be automatically done, can be
> > automatically "un-done". That's like locking the door but leaving the key
> > under the mat.
>
> I don't believe that is true in this case. For GPG to encrypt to a key,
> it only needs the public key; to decrypt it needs both the private key
> and the passphrase. As long as the machine doing the encrypting doesn't
> have a copy of the private key, it should be quite difficult for someone
> to automatically undo the encryption.

I interpreted this original response along the lines of, "Note that you
can automate the encrypting process, but someone else might come along,
and either remove it, or save originals someplace else.."

Cheers

-- 
The Bill of Rights: 7 out of 10 rights haven't been sold yet! Contact
your congressman for details how *you* can buy one today!




Relevant Pages

  • Re: RA doesnt work after encrypting in XP
    ... >I am setting up a standard procedure for encrypting the data folders on ... > as deleting the RA private key using certmgr.msc. ... This works fine and I am able to decrypt them as ...
    (microsoft.public.win2000.security)
  • Re: Remote signing of large files
    ... about 'Remote signing of large files': ... the signing of this message digest. ... [Encrypting with the private key allows anyone ... of the private key, or that the private key has been compromised.] ...
    (Debian-User)
  • Re: identity file permissions
    ... to the LDAP server and make their homedir. ... even if a user COULD get to the private key on the ... decent example of where sharing a single private key among the users ...
    (SSH)
  • Re: cryptological confusion
    ... it's not so much a misconception as a change in the ... preferred phraseology. ... the "encrypting with the private key" ...
    (sci.crypt)
  • Re: Encrypt with Private key, Decrypt with Public Key (RSACryptoServiceProvider)
    ... Encryption with an RSA private key is mainly used for generating ... and then send it to someone so they can verify (with your public key, ... > portion/public portion, mainly because I AM CURIOUS AND I WONT GIVE MY ... > public portion of the key if I am encrypting with the private portion. ...
    (microsoft.public.dotnet.security)