4 ms·
I wrote a short blog post comparing PGP and Age a few weeks ago. Some may find it of interest: https://www.go350.com/posts/age-file-encryption/ https://www.go35
by _wldu 5y ago
I wrote a short blog post comparing PGP and Age a few weeks ago. Some may find it of interest: https://www.go350.com/posts/age-file-encryption/ https://www.go350.com/posts/age-file-encryption/
- aidenn0 5y agoThanks for that. One thing that wasn't mentioned is whether or not private keys can be stored in HSMs with age. I'm guessing since the authors recommend against password-protecting private keys that the answer is "no" but that's one reason that I pick GPG for things.
- FiloSottile 5y agoWe designed the plugin protocol (https://hackmd.io/@str4d/age-plugin-spec https://hackmd.io/@str4d/age-plugin-spec) and generally the age recipient/identity structure specifically to enable the use of hardware or remote keys! For example, https://github.com/str4d/age-plugin-yubikey https://github.com/str4d/age-plugin-yubikey makes it very easy to use PIV tokens, including YubiKeys, with age. (Well, for now with rage, since plugin support is coming in age v1.1.0.) I argue against password-protecting keys by default because, unlike using hardware tokens, it doesn't protect against many threat models.
- jeremyw 5y agoCan you clarify re not password-protecting keys? If I run GUI applications, let's say, as my user -- as is the default in most operating systems -- they have general access to my files, including my keys-as-files, no? (Putting aside some minor restrictions MacOS and others are slowly making.)
- FiloSottile 5y agoYes, and they can also replace the age binary with one that uploads the password as soon as you type it. There is no meaningful security boundary to defend. We implemented support for password-encrypted keys for the cases where you store the key file in, say, Dropbox.
- darkwater 5y agoBut in the "age binary replaced" threat scenario, isn't just gameover even with hardware keys? Eg. the same exact age code with an extra call after the print password to stdout that uploads it somewhere?
- FiloSottile 5y agoThe difference with hardware keys is that the primary key can’t be exfiltrated, and only one secret can be decrypted per physical touch, so rotation and recovery are possible without invalidating all secrets.
- jeremyw 5y agoI suppose in a homebrew situation, but not if age is root-installed, correct? It seems like that's a hard boundary.
- FiloSottile 5y agoI mean, most users don't root-install, but anyway the GUI application can drop a different age binary higher on the user's PATH. Or change their shell. Or a million other things. There really isn't a point to defending against code running unsandboxed on a single-user machine.
- ulrikrasmussen 5y agoI password protect my key for the sole threat model of me physically losing my device. I am aware that all other threat models that involve someone taking remote control of my device are not fully protected against, but it at least requires significantly more effort on their part versus just doing a scan for private keys on the file system.
- SEJeff 5y agoWhy not use disk encryption for this threat model?
- deleted 5y ago[deleted]
- tex0 5y agoReally looking forward to age 1.1.0 so we can give gopass mature age support as well. Stupid question: Are only YubiKeys supported or also other hardware tokens?
- FiloSottile 5y agoage-plugin-yubikey supports all PIV tokens. There are other 3rd party plugins in development for other hardware tokens. The v1.1.0 Go API will be able to drive arbitrary plugins, so you should be able to integrate with all of them!
- chx 5y agoAs I was reading this, my thinking was 1. What's your threat model? 2. Have you read James Mickens: This World of Ours?