9 ms·
Using GPG to Encrypt Your Data
- kondbg 10y agoIs there a benefit in using symmetric encryption vs specifying yourself as a recipient?
- RJIb8RBYxzAMX9u 10y agoUnless compatibility with gpg is a requirement, I think scrypt[0] is a much simpler tool for file encryption. The utility is meant to showcase the KDF of the same name. It's very simple and has virtually no parameters. So: $ xz -k elrond_minutes.txt $ scrypt enc elrond_minutes.txt.xz elrond_minutes.txt.xz.enc $ signify -S \ -s vilya.key \ -m elrond_minutes.txt.xz.enc \ -x elrond_minutes.txt.xz.enc.sig $ rm elrond_minutes.txt{,.xz} Signing the final output is probably extraneous; I think scrypt uses a HMAC. This involves invoking multiple tools, but since each tool only does one thing it's much easier to reason about, and I prefer this over using an omnibus tool like gpg. [0] https://github.com/Tarsnap/scrypt https://github.com/Tarsnap/scrypt
- agumonkey 10y agoMy paranoid self wanted to replace rm with shred.
- twr 10y agoYou can just pipe xz instead, although you may want to shred the original file: xz < file | scrypt enc - > file.xz.enc And I agree: scrypt (the program) is much better for password encrypting documents. It is only a few thousand lines of readable code; it uses modern algorithm choices (scrypt, AES256-CTR, HMAC-SHA256), with no alternatives; there isn't any configuration involved; and it's written by a respected author.
- RJIb8RBYxzAMX9u 10y agoshred is ineffective if you're using a CoW FS, and probably less effective on a journaling FS, and those probably covers 99% of all the FS people use today. Just use FDE.
- SeaDude 10y agoThe HECC site here is one of the best support sites i've ever seen. Very logically laid out KB, news, ask a question, etc. thanks for the link
- parfe 10y ago>We suggest that you include five words of 5-10 letters in size, chosen at random, with spaces, special characters, and/or numbers embedded into words. >You need to be able to recall the passphrase that was used to encrypt the file. Why bother writing security guidelines which are impossible for a human to follow? edit: Try recalling any passphrases generated by the command below, and that's before the random sprinkling of punctuation. grep -E "^[a-z]{5,10}$" /usr/share/dict/words | shuf -n5 | tr '\n' ' '
- HappyTypist 10y agoIs it really impossible for a human to follow? "Shiny C0rrect H0rse Battery Staple!"
- sib 10y agoFor one specific site, no. But if you have 100-200 different passwords to remember, it's impossible for most people.
- jesseb 10y agoAt work I constantly deal with people who can't remember passwords as short as 8 characters, you have to remember we're not representative of the average person.
- keymone 10y agoyou should ask them what they prefer - remembering 8 random characters or 4 random words
- LordKano 10y agoThat's a good long term solution but when policies force you to change your password every 45 days, it falls apart. In my experience, overly restrictive password policies force users to choose passwords that are less secure and easier to remember.
- 10y ago
- discreditable 10y agoWhy would they not use asymmetric encryption?
- gcp 10y ago...and why encrypt stuff transferred with scp?
- 45h34jh53k4j 10y agobecause encryption in transit != encryption at rest. Maybe you don't trust the server you are scp'ing the data to, with encryption at rest you dont' need to.
- gcp 10y agoThat's not what the documentation is about, though: ==== Use GPG with the cipher AES256, without the --armour option, and with compression to encrypt your files during inter-host transfers. GPG Encryption helps protect your files during inter-host file transfers (for example, when using the scp, bbftp, or ftp commands). We recommend GPG (Gnu Privacy Guard), an Open Source OpenPGP-compatible encryption system. === scp shouldn't be in that list.
- falcolas 10y agoIf your goal is to transfer securely from person to person, 'scp' generally means there's a common server you're accessing - not that you're 'scp'ing directly to the other user's machine. Keeping it secure when "at rest" on the remote server would ensure it's securely transferred between the two end points.
- jph 10y agoNASA has historically done at least some open transfers, such as HTTP, FTP, etc. Using GPG for these is good. And it keeps the file encrypted at rest too.
- brockers 10y ago
- jph 10y agoFor GPG symmetric encryption, the kind the article describes, here are the best options I've found for my typical case: gpg --symmetric \ --cipher-algo aes256 \ --digest-algo sha256 \ --cert-digest-algo sha256 \ --compress-algo none -z 0 \ --quiet --no-greeting \ --no-use-agent "$@" I keep this command here: https://github.com/SixArm/gpg-encrypt The options are chosen to balance tradeoffs of convenience, strength, and portability.
- api 10y agoThis illustrates what's wrong with GPG: it's too hard to use. Why so many arguments for a common task? Why aren't the defaults acceptable?
- RMarcus 10y agoThe defaults are acceptable, and will produce a symmetrically encrypted file that can be quickly decrypted on even low-powered ARM cores in a reasonable amount of time. These suggestions strike a different balance between protection and speed.
- tptacek 10y agoYou can safely just use "gpg -c" to encrypt files.
- brotherjerky 10y agoDoes `-no-use-agent` work? I see this in man: --no-use-agent This is dummy option. gpg always requires the agent.
- jwilk 10y agoContemporary versions of GnuPG (>= 2.1 IIRC) always use gpg-agent, and this option does nothing except producing a warning: gpg: WARNING: "--no-use-agent" is an obsolete option - it has no effect
- jph 10y agoI'll remove it now. It was useful to have (for me) for GPG version 1 when I connected to machines via SSH and didn't want a GPG agent pop up UI, and didn't have an easy way to change the GPG agent settings.
- oripel 10y agoKey stretching is critical for password-based encryption, and gpg's s2k options are vulnerable to GPU acceleration. Command-line tools to encrypt with bcrypt/scrypt are common and may be a better option.
- woliveirajr 10y agoThere's the [2015] which should be included.
- rdslw 10y agoNo it shouldnt. It imposes (false) perception that anything not from today is old/not fresh/known/bad knowledge. It is not true. This hunt for dates in titles on HN is bad and it's awitch hunt these days. Disclaimer: I'm not an author nor submitter.
- teddyh 10y agoThis is “Hacker News”.
- grzm 10y agoThe "News" is a bit of a misnomer. Any submission that "gratifies intellectual curiosity" is on-topic, regardless of age.
- grzm 10y agoAdding the year does nothing other than let people know when it was published and gives it some context. You're reading too much into this. The practice goes back at least 2½ years.
- rdslw 10y agoIf we're talking about GPG, please pay attention to https://www.passwordstore.org/ https://www.passwordstore.org/ which is really cool, open source password manager built on GPG.
- openplatypus 10y agoAnd QtPass with it. https://qtpass.org/ https://qtpass.org/
- dvko 10y agoI switched from OSX to Linux a few months ago and had to find an alternative for 1Password. Pass has been great, I love its simplicity. Not having a browser add-on to retrieve passwords was feeling like a step back in terms of convenience though. That's why I built & open sourced browserpass [1], a browser extension for Pass. It uses Native Host Messaging to securely retrieve passwords, so no crazy port listening as some other open-sourced add-ons do (which is a terribly bad idea). [1] https://github.com/dannyvankooten/browserpass https://github.com/dannyvankooten/browserpass
- ballpointcarrot 10y agoIn addition, there's a Android client for it as well, so you can take your passwords on the go: https://play.google.com/store/apps/details?id=com.zeapo.pwdstore https://play.google.com/store/apps/details?id=com.zeapo.pwds...
- veeti 10y agoIs there anything like this that doesn't leak the folder structure in plaintext? Manually obfuscating site names would be very tedious.