3 ms·
My point was that for a non-pgp aware imap client to read the encrypted emails, the passphrase needs to be somewhere, probably in RAM all the time, making it a
by slug 13y ago
My point was that for a non-pgp aware imap client to read the encrypted emails, the passphrase needs to be somewhere, probably in RAM all the time, making it a target, so if there's an exploit, having it encrypted or not is moot. It solves the 'steal box' problem and since it's not spy stuff, we don't have to worry about cold boot attacks ;)
On a desktop, the pgp credentials either exists momentarily (user input) or through an agent, so at first sight it would seem that would be safer, although then we could also argue that a desktop is probably not as safe as this box due to all the other software that is run by the user.
- radiospiel 13y agoUltimately this is a decision between usability and security, and I am afraid there is no good answer here. We still do our best to prevent key theft, even in the case of someone hacking into a running box. There is only one process with access to the keys, which runs in a separate system account (each software component runs under its own account anyways) and which is not accessible from the outside. Still, one could potentially hack into the system and become root.. but this is less likely to happen on a separate box than on a full-blown desktop (with the average user giving out his/her root password whenever some installer asks for it).