5 ms·
After I wrote my comment, I actually came to the realization that there probably is some "ssh agent" equivalent out there. This sounds very much like what I wo
by markild 12y ago
After I wrote my comment, I actually came to the realization that there probably is some "ssh agent" equivalent out there.
This sounds very much like what I would want, yes!
- p4bl0 12y agoYes, there is indeed gpg-agent [1]. And you can use it as your ssh-agent too, so you only need to run one instead of both. I agree with you that it would be awesome to have the option to use gpg-agent from that sort of browser extensions. Actually if browsers where able to communicate with gpg-agent it would be easy to use that as backend to store randomly generated password for web apps and services. [1] http://manpages.debian.org/cgi-bin/man.cgi?query=gpg-agent http://manpages.debian.org/cgi-bin/man.cgi?query=gpg-agent
- XorNot 12y agoI don't like seahorse. I think if we're going to do secure element password storage of some sort, we need to standardize on a file format and make it cross-platform. I'm willing to settle for standardizing on the interop format, but I'd still want it to be cross-platform. I'm not a fan of various somewhat arbitrary "store your secrets" systems coming with an operating system - they're slightly too magical to keep track of and secure, or synchronize. GPG for example has no real way to synchronize keys across devices, but it's unclear how many or how often you'd want to use different keys other then "clearly more then once, less then all the time".
- chimeracoder 12y ago> I don't like seahorse. I think if we're going to do secure element password storage of some sort, we need to standardize on a file format and make it cross-platform. I don't understand. gpg-agent is not dependent on Seahorse[0], though the two are often used together. > I'm willing to settle for standardizing on the interop format, but I'd still want it to be cross-platform. "Cross-platform" for formats is usually limited by the cooperation of the proprietary providers, not the FOSS ones. In this case, OS X does not provide an open standard format (AFAIK), though it's trivial to create an import/export utility[1] that could be used to synchronize with gnome-keyring and the like. > I'm not a fan of various somewhat arbitrary "store your secrets" systems coming with an operating system - they're slightly too magical to keep track of Could you elaborate on your complaint here? I think OS X's keychain works reasonably well in this respect (on by default, single point of storage for all keys). UX is the biggest challenge these days when it comes to cryptography, and having the keychain "just work" while also being a single point of storage for the device is a notable accomplishment. > GPG for example has no real way to synchronize keys across devices, but it's unclear how many or how often you'd want to use different keys other then "clearly more then once, less then all the time". Subkeys can be used to address the issue of multiple devices (multiple laptops, or laptop + phone). You might want to use different master keys for work and personal use. GPG supports this, though the interface for selecting a private key could certainly be improved. [0] https://www.gnupg.org/related_software/frontends.html https://www.gnupg.org/related_software/frontends.html [1] https://github.com/juuso/keychaindump https://github.com/juuso/keychaindump
- mike-cardwell 12y agoIn fact, gpg-agent is a required component of GnuPG version 2, which was released ~8 years ago.