5 ms·
If you have your keys on an air gapped computer with an encrypted hard-disk, I don't see the need to use an additional password on the private keys.
by trizinix 9y ago
If you have your keys on an air gapped computer with an encrypted hard-disk, I don't see the need to use an additional password on the private keys.
- kakarot 9y agoOne possible benefit is giving you enough time to discover the breach and rotate keys before the keys are compromised
- hateduser2 9y agoIf they somehow break the encryption on your hard disk it’s just more security.. isn’t that what security’s all about? Getting the most safety you can get? What need is there to have an encrypted hard drive if your computer is air gapped? It’s just a better safer idea, no?
- hyperfekt 9y agoThe assumption is that the encryption can only be broken via an evil-maid attack. If you are victim of such an attack, the encryption of the file is broken as well.
- avar 9y agoSecurity is not about getting the most safety you can get. Otherwise why stop there? You could store the password protected private key itself as an encrypted file on the encrypted disk, and add one more layer, or double-encrypt it and add yet another layer etc.
- parenthephobia 9y agoIf you mean air-gapped literally, that seems unuseful. Wouldn't you want the keys on the computer that's going to use them? And then, wouldn't you want to make it hard to copy the unencrypted private keys? (I'm assuming we're talking about SSH keys.) OTOH, it could be neat to run an ssh agent in a key-holding qube and forward that to whatever qubes need to use your SSH keys, using `ssh-add -c` so that key use must be confirmed in the key-holding qube.
- goatsi 9y agoSound exactly like split-GPG https://www.qubes-os.org/doc/split-gpg/ https://www.qubes-os.org/doc/split-gpg/