Re: public accounts / PGP / passphrases
17 Dec
2003
17 Dec
'03
11:17 p.m.
Could someone please elaborate on the foolishness of using PGP with a passphrase on a public machine (as I do) ? Am I wrong in thinking that my secret key is useless to an intruder until she guesses my passphrase ?
The sys admin can change the kernel running on your machine. A special kernel can be built so that when a particular user is typing on a tty and the executing process is named "pgp" then all keystrokes they type are recorded into a file for the administrator to read later on. The local machine must be part of the trusted computing base. /r$
8177
Age (days ago)
8177
Last active (days ago)
0 comments
1 participants
participants (1)
-
Rich Salz