Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #195003

Re: encryption

From David Wright <deblis@lionunicorn.co.uk>
Newsgroups linux.debian.user
Subject Re: encryption
Date 2018-04-23 10:50 +0200
Message-ID <vHFkB-7QB-5@gated-at.bofh.it> (permalink)
References (1 earlier) <vGOgh-6Fy-5@gated-at.bofh.it> <vH2CB-7Gd-5@gated-at.bofh.it> <vH6Gd-1P9-1@gated-at.bofh.it> <vHpSx-6mj-1@gated-at.bofh.it> <vHqlA-6vF-11@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On Sun 22 Apr 2018 at 17:46:12 (+0100), Brian wrote:
> On Sun 22 Apr 2018 at 11:10:24 -0500, David Wright wrote:
> 
> > On Sat 21 Apr 2018 at 12:43:54 (-0700), David Christensen wrote:
> > > 
> > > On 04/21/18 08:20, Brian wrote:
> > > >On Fri 20 Apr 2018 at 17:07:10 -0700, David Christensen wrote:
> > 
> > > >> As scrypt is going to prompt you for a passphrase anyway, why don't
> > > >> you leave the script unencrypted and revise it to prompt for the
> > > >> "important password"?
> > > 
> > > Please comment.
> > 
> > One might assume that the script could have a unencrypted option to
> > select between a number of "important passwords", each of which might
> > be a long, complex, unmemorable string, subject to frequent changes,
> > and (or because) exposed to the rest of the world.
> > 
> > OTOH the passphrase protecting the script might be a single, simple,
> > fixed, memorable string only exposed to users on the machine in question.
> 
> I thought I had indicated my intention to take the advice offered and
> put the important password (a master password) in a separate file and
> source it from the script.

Sure. But the question was posed again, so I came up with one
possible reason not to prompt for the "important password".
(What made it gain that epithet hadn't been revealed at that point.)

> The script itself does not need encrypting if the master password is
> not in it. However, I would not want the separate file unencryted
> because the master password gives access to passwords for all sorts of
> websites.
> 
> Users actually have to know this master password. It is a long phrase,
> not too hard to memorise but tedious to type. As I have said, encrypting
> the separate file with scrypt allows me to get the decryption password
> down to a more user-friendly 14 characters. The prompting for the
> password is done by scrypt. There is no point in multiple people having
> different passwords. All users here are trusted.

If users are trusted, then the discussion on hiding information from
ps becomes moot, doesn't it? (That was the more interesting part of
the discussion for me.)

Cheers,
David.

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

encryption Brian <ad44@cityscape.co.uk> - 2018-04-20 21:40 +0200
  Re: encryption Greg Wooledge <wooledg@eeg.ccf.org> - 2018-04-20 22:00 +0200
  Re: encryption David Christensen <dpchrist@holgerdanske.com> - 2018-04-21 02:10 +0200
    Re: encryption Brian <ad44@cityscape.co.uk> - 2018-04-21 17:30 +0200
      Re: encryption john doe <johndoe65534@mail.com> - 2018-04-21 17:40 +0200
        Re: encryption David Christensen <dpchrist@holgerdanske.com> - 2018-04-21 22:00 +0200
          Re: encryption john doe <johndoe65534@mail.com> - 2018-04-22 08:30 +0200
            Re: encryption David Christensen <dpchrist@holgerdanske.com> - 2018-04-22 20:30 +0200
      Re: encryption Glenn English <ghe2001@gmail.com> - 2018-04-21 19:00 +0200
        Re: encryption David Christensen <dpchrist@holgerdanske.com> - 2018-04-21 22:30 +0200
      Re: encryption David Christensen <dpchrist@holgerdanske.com> - 2018-04-21 21:50 +0200
        Re: encryption David Wright <deblis@lionunicorn.co.uk> - 2018-04-22 18:20 +0200
          Re: encryption Brian <ad44@cityscape.co.uk> - 2018-04-22 18:50 +0200
            Re: encryption David Wright <deblis@lionunicorn.co.uk> - 2018-04-23 10:50 +0200
              Re: encryption Brian <ad44@cityscape.co.uk> - 2018-04-23 13:20 +0200
                Re: encryption David Wright <deblis@lionunicorn.co.uk> - 2018-04-24 20:50 +0200
  Re: encryption David Wright <deblis@lionunicorn.co.uk> - 2018-04-21 18:40 +0200
    Re: encryption Brian <ad44@cityscape.co.uk> - 2018-04-21 20:20 +0200
      Re: encryption David Wright <deblis@lionunicorn.co.uk> - 2018-04-21 21:00 +0200
        Re: encryption Brian <ad44@cityscape.co.uk> - 2018-04-21 21:20 +0200
          Re: encryption David Christensen <dpchrist@holgerdanske.com> - 2018-04-21 23:30 +0200
          Re: encryption David Wright <deblis@lionunicorn.co.uk> - 2018-04-22 04:30 +0200
            Re: encryption Curt <curty@free.fr> - 2018-04-22 11:20 +0200
              Re: encryption Reco <recoverym4n@gmail.com> - 2018-04-22 11:50 +0200
                Re: encryption Brian <ad44@cityscape.co.uk> - 2018-04-22 19:10 +0200
      Re: encryption David Christensen <dpchrist@holgerdanske.com> - 2018-04-21 22:50 +0200
    Re: encryption David Christensen <dpchrist@holgerdanske.com> - 2018-04-21 22:10 +0200
      Re: encryption David Wright <deblis@lionunicorn.co.uk> - 2018-04-22 04:00 +0200
        Re: encryption Brian <ad44@cityscape.co.uk> - 2018-04-22 17:40 +0200
          Re: encryption Richard Hector <richard@walnut.gen.nz> - 2018-04-23 08:00 +0200
            Re: encryption Andrew McGlashan <andrew.mcglashan@affinityvision.com.au> - 2018-04-23 09:00 +0200
        Re: encryption David Christensen <dpchrist@holgerdanske.com> - 2018-04-22 20:10 +0200

csiph-web