PGP help and comments.

Jim McCoy mccoy at ccwf.cc.utexas.edu
Sat Apr 3 23:58:38 PST 1993


J. Michael Diehl <mdiehl at triton.unm.edu> writes:
> 
> I would like to use pgp on the mainframes, but don't want to store my secret
> key on their disks.   Would it be possible to have pgp accept it's secret key
> via stdin.  I could do an ascii upload of my secret key and never expose my
> key to disk-storage.

This is even more dangerous than storing it on the disks of a multi-user
machine.  Unless you are running in a kerberos environment it is trivial to
snoop your upload off the network, and even without that weakness you are
exposing yourself to the same problem that the docs mention (it is really
pretty easy to scan someone's terminal input) only you are giving them the
key outright instead of only giving them the passphrase to your key.

Bad idea.

jim






More information about the cypherpunks-legacy mailing list