5 ms·
I really wish I wouldn't have to store the private key together with a browser extension I don't trust (no offense to the author(s)). It would be amazing if Wi
by markild 12y ago
I really wish I wouldn't have to store the private key together with a browser extension I don't trust (no offense to the author(s)).
It would be amazing if Windows, Mac and Linux all would support some sort of "safe" gpg/pgp storage. I don't remember if I'm making this up, but i believe the OS X keyring can do this. There really should be no reason why every application should roll their own storage and interaction of the private key.
- Link- 12y agoI've been using Mailvelope for a while, it's a good extension and works well. But yes, I share the same frustration regarding the private key storage in the browser.
- galapago 12y agohttps://github.com/toberndo/mailvelope/issues/190 https://github.com/toberndo/mailvelope/issues/190 Also, the problem is that you can't re-use the keyring from GPG, since they are using openPGP.js and the duplication is inevitable..
- peterwwillis 12y agoWhy can't you use the GPG keyring? Just implement the protocol in your .js app and talk to a keyring server. This is actually quite necessary if you want to sandbox your browser away from sensitive files like private keys...
- subway 12y agoThis. At the very least, these extensions could provide an option to communicate via the GnuPG Agent protocol.
- markild 12y agoAfter I wrote my comment, I actually came to the realization that there probably is some "ssh agent" equivalent out there. This sounds very much like what I would want, yes!
- p4bl0 12y agoYes, there is indeed gpg-agent [1]. And you can use it as your ssh-agent too, so you only need to run one instead of both. I agree with you that it would be awesome to have the option to use gpg-agent from that sort of browser extensions. Actually if browsers where able to communicate with gpg-agent it would be easy to use that as backend to store randomly generated password for web apps and services. [1] http://manpages.debian.org/cgi-bin/man.cgi?query=gpg-agent http://manpages.debian.org/cgi-bin/man.cgi?query=gpg-agent
- XorNot 12y agoI don't like seahorse. I think if we're going to do secure element password storage of some sort, we need to standardize on a file format and make it cross-platform. I'm willing to settle for standardizing on the interop format, but I'd still want it to be cross-platform. I'm not a fan of various somewhat arbitrary "store your secrets" systems coming with an operating system - they're slightly too magical to keep track of and secure, or synchronize. GPG for example has no real way to synchronize keys across devices, but it's unclear how many or how often you'd want to use different keys other then "clearly more then once, less then all the time".
- chimeracoder 12y ago> I don't like seahorse. I think if we're going to do secure element password storage of some sort, we need to standardize on a file format and make it cross-platform. I don't understand. gpg-agent is not dependent on Seahorse[0], though the two are often used together. > I'm willing to settle for standardizing on the interop format, but I'd still want it to be cross-platform. "Cross-platform" for formats is usually limited by the cooperation of the proprietary providers, not the FOSS ones. In this case, OS X does not provide an open standard format (AFAIK), though it's trivial to create an import/export utility[1] that could be used to synchronize with gnome-keyring and the like. > I'm not a fan of various somewhat arbitrary "store your secrets" systems coming with an operating system - they're slightly too magical to keep track of Could you elaborate on your complaint here? I think OS X's keychain works reasonably well in this respect (on by default, single point of storage for all keys). UX is the biggest challenge these days when it comes to cryptography, and having the keychain "just work" while also being a single point of storage for the device is a notable accomplishment. > GPG for example has no real way to synchronize keys across devices, but it's unclear how many or how often you'd want to use different keys other then "clearly more then once, less then all the time". Subkeys can be used to address the issue of multiple devices (multiple laptops, or laptop + phone). You might want to use different master keys for work and personal use. GPG supports this, though the interface for selecting a private key could certainly be improved. [0] https://www.gnupg.org/related_software/frontends.html https://www.gnupg.org/related_software/frontends.html [1] https://github.com/juuso/keychaindump https://github.com/juuso/keychaindump
- CalRobert 12y agoI believe Debian (at least Kali, which I've used last) supports this as well.
- malka 12y agoI do not see more reasons to trust the OSX Keyring, than to trust a browser extension.
- knodi123 12y agoDo you think it's better to put all your eggs in one basket, or in two baskets?
- TeMPOraL 12y agoPrivate keys are not fungible, if you lose one you're done, game over. By putting them in more places you're making yourself strictly less secure. Also, with that old and worn proverb about eggs and baskets, if having none of your eggs is equivalent in value to you for having only some but not all (i.e. you must have exactly all of them, or else you fail), then putting them all in one basket is better than putting in two (or more).
- derefr 12y ago> By putting them in more places you're making yourself strictly less secure. If you're trying to minimize baskets, though, then having two very-secure baskets is much better than having N baskets ever-growing because you can't trust in their sturdiness. Which is to say, putting a USB with your private key on it in your safe-deposit box at your bank, for example, means being more assured about the fact that you'll have a backup copy, meaning you then feel safe excluding it from local hard-disk backups and synchronized remote backups/cloud storage, and have no reason to have it on any computers you aren't currently using for the sake of having somewhere to import it from. In a sense, you've added one vector of attack, but in practice, you've removed several.
- madeofpalk 12y agoAt least in this case, there are a lot more eyes and attention on cracking OS X Keychain compared to this browser extension which most will forget about in a week or so.
- mike-cardwell 12y agoThis is exactly what gpg-agent is for. Browsers should talk to a locally running gpg-agent, then it would automatically get support for things like OpenPGP smart cards. Then you don't even need to trust your OS with access to your keys, let alone your browser.
- lifeisstillgood 12y agoThis sounds so obvious yet I cannot find anything on the Blue Googles about anyone even trying. But yes, obviously. (https://blog.mozilla.org/security/2013/02/13/using-cryptostick-as-an-hsm/ https://blog.mozilla.org/security/2013/02/13/using-cryptosti... close ... so close)
- ultramancool 12y agoMailvelope could potentially use a plugin to do this locally, though it may complicate things.
- elehack 12y agoIIRC, the gpg-agent is sadly not that capable or intelligent. In theory, it should be usable for this. In practice, I believe the agent actually just retrieves the passphrase and hands it to the requesting program, which is then responsible for actually working with the private key. So it doesn't keep your keys safely out of the hands of 'normal' programs, even though it seems like it should. Although it is somewhat confusing, and gpg-agent seems to mediate access to smartcards. Protocol docs here: https://www.gnupg.org/documentation/manuals/gnupg/Agent-Protocol.html https://www.gnupg.org/documentation/manuals/gnupg/Agent-Prot... The ssh-agent, on the other hand, does keep the key material out of the ssh client executable.