3 ms·
Comment about pass... (looks like a great tool btw) you mention in the man page that > Multiple gpg-ids may be specified, in order to encrypt each password wit
by opmac 10y ago
Comment about pass... (looks like a great tool btw) you mention in the man page that
> Multiple gpg-ids may be specified, in order to encrypt each password with multiple ids.
That should technically reduce security, when encrypting the same secret with multiple IDs, as it gives a potential attacker more data to work with.
I suggest adding some randomness when encrypting with each key and having pass hide it from the end user when decrypting.
- e12e 10y agoYou're aware of an attack on RSA that weakens it when a short random string is encrypted with a handful of RSA keys as opposed to a single key? Afaik supplying multiple ids to gpg simply re-encryps the same symmetric key for multiple recipients - the plaintext is turned into a single cipher text.
- hackcasual 10y agoThere is an attack against RSA if you encrypt very small values with a small exponent and insecure padding. GPG generates a large symmetric encryption key, and uses that to encrypt the message, uses 65537 (as is considered good practice) as its exponent, and uses a cryptographically appropriate PKCS#1v1.5 padding scheme As far as I'm aware, there's no reduction in security by encrypting to multiple public keys (other than increased risk of compromising one of the keys).