5 ms·
As a user, I also often feel like `gpg` brings a lot of annoying accidental complexity to `pass`, (like the need to "ultimately trust" keys before they become u
by HotHotLava 5y ago
As a user, I also often feel like `gpg` brings a lot of annoying accidental complexity to `pass`, (like the need to "ultimately trust" keys before they become usable) but on the other hand it enables integration with hardware tokens like Yubikeys and in extension mobile devices (via openkeychain) that as far as I know wouldn't be possible with a more modern age-based backend.
- beagle3 5y agoSSH has included file encryption for a few versions now, and iirc supports yubikeys — probably would be more useful a backend than age.
- tialaramex 5y ago> SSH has included file encryption for a few versions now Mmm. I don't think so. Recent OpenSSH includes file signatures not encryption.
- beagle3 5y agoAhh, you are correct, I misremembered.
- _abox 5y agoYep the integration with Yubikey is amazing. Both on mobile and desktop <3
- yepguy 5y agohttps://github.com/str4d/age-plugin-yubikey https://github.com/str4d/age-plugin-yubikey
- upofadown 5y ago>like the need to "ultimately trust" keys before they become usable Did you have to do that manually at one time? All the keypairs that I make start out that way when created. When creating a keypair for pass all you have to do is generate the key using defaults while remembering a bit of the user ID to give to pass.
- loulouxiv 5y agoI had to do it when importing keys on another device
- HotHotLava 5y agoYes, every time I want to set it up on a new device I have to import and trust all public keys that it should encode to; and if that device gets its own gpg key then that key also has to be distributed to and trusted at all prior sites. Which isn't very often, but still somewhat regularly (ie. new laptop, new yubikey, formatted hard drive, etc.) I think it would be a great addition if pass could actually automate this by storing all relevant public keys internally.
- upofadown 5y agoAh, yes that is a nuisance. GPG has the "--export-ownertrust" and "--import-ownertrust" commands to make that sort of thing less tedious. In general I think you are supposed to only have a one or a few "ultimately trusted" keys and then distribute that trust by signing the rest. So once you change the trust on one key the trust distributes automatically.