Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-Id: <20110403203844.2e400400.michael.s.gilbert@gmail.com>
Date: Sun, 3 Apr 2011 20:38:44 -0400
From: Michael Gilbert <michael.s.gilbert@...il.com>
To: oss-security@...ts.openwall.com
Subject: Re: Closed list

Josh Bressers wrote:

> > 
> > Benji's trolling does raise a couple real issues. The private keys and
> > passphrases of those responding here have now become highly lucrative
> > targets for attackers. Hence, everyone on this new list needs to use good
> > practices to keep their keys, hard drives, and computers safe.  There
> > should probably be some common guidelines for key safety for all
> > participants.
> > 
> 
> I don't buy this. It's really no secret who is involved in open source
> security, or most any security in general. If you're in this business and
> don't worry about such threats all the time, you're probably in the wrong
> field.
> 
> I think keeping this wide open will make us better at what we do. This is a
> bit silly I agree, but it's also brutally honest.

I'm actually not arguing in opposition to participant transparency.  In
fact I am 100% supportive of that.  Instead, I'm simply stating
that there is an increased threat to those participating (due to the
value attackers will find in being able to decrypt your private
traffic).

I was hoping to spur a discussion on some common practices to mitigate
this bigger threat (perhaps starting with a requirement to use pgp/gpg
smart cards so that an account compromise only leads to a passphrase
compromise rather than a key+passphrase compromise).

Best wishes,
Mike

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.