Skip to main content

encryption - if one doesn't care about protecting a gpg secret key, is it still as secure as using gpg --symmetric?


Each of Alice and Bob is using gpg just to protect his/her own personal files and not using it as a way to send encrypted text to others. Alice has generated a key (gpg --gen-key) that she uses to encrypt/decrypt her personal files (gpg --encrypt --recipient="Alice Personal" alice.secrets.txt and gpg --decrypt alice.secrets.txt.gpg). She knows that in order to read and write to alice.secrets.txt.gpg in her another computer, she needs to export her key (both public key and private key) to her second computer, using commands like:


gpg --armor --export "Alice Personal" > alice.personal.public.key.txt
gpg --armor --export-secret-key "Alice Personal" > alice.personal.private.key.txt

and


gpg --import alice.personal.public.key.txt
gpg --import alice.personal.private.key.txt

So she decides to put her encrypted personal files (alice.secrets.txt.gpg) and her key (alice.personal.public.key.txt and alice.personal.private.key.txt) on a cloud sync service for convenience. Because alice.personal.private.key.txt is on cloud, a third party who may get access to her files on cloud has access to the first of the following two, but not the second.




  • something she has: alice.personal.private.key.txt




  • something she knows: the passphrase to unlock the secret key




She's giving up protecting the first in return for convenience.


On the other hand, Bob uses symmetric encryption to protect his secrets (gpg --symmetric bob.secrets.txt and gpg --decrypt bob.secrets.txt.gpg). He also puts his encrypted personal files on a cloud service. To read and write to bob.secrets.txt.gpg on his another computer, he just needs to successfully recall his passphrase.


Maybe Alice and bob should just use Truecrypt or Boxcryptor. Anyway, question is, are Alice's secrets as safe as Bob's secrets provided that their passphrases are equally good?



Answer



Alice's approach is ever so slightly safer than Bob's. Every encrypted file gets a new symmetric key, which means that:



  • You'll have to break the symmetric key separately for each file instead of once, and those keys are usually easier to break than proper RSA keys (lower key space for higher performance, as we can't lose time with every new message, be it a document or a connection, and RSA doesn't have to be efficient one the key is generated as we usually use it to cypher a symmetric key used for the rest of the document).

  • You might avoid attacks when both the cyphered and uncyphered documents are know. If Eve knows has the original of document and the version encrypted for Alice, it might make it easier to find the key and use it for all other documents.

  • You might avoid attacks made available by knowing many encrypted messages, which could be similar to what we already know with RSA and low exponents.


Comments

Popular Posts

Use Google instead of Bing with Windows 10 search

I want to use Google Chrome and Google search instead of Bing when I search in Windows 10. Google Chrome is launched when I click on web, but it's Bing search. (My default search engine on Google and Edge is http://www.google.com ) I haven't found how to configure that. Someone can help me ? Answer There is no way to change the default in Cortana itself but you can redirect it in Chrome. You said that it opens the results in the Chrome browser but it used Bing search right? There's a Chrome extension now that will redirect Bing to Google, DuckDuckGo, or Yahoo , whichever you prefer. More information on that in the second link.

linux - Using an index to make grep faster?

I find myself grepping the same codebase over and over. While it works great, each command takes about 10 seconds, so I am thinking about ways to make it faster. So can grep use some sort of index? I understand an index probably won't help for complicated regexps, but I use mostly very simple patters. Does an indexer exist for this case? EDIT: I know about ctags and the like, but I would like to do full-text search. Answer what about cscope , does this match your shoes? Allows searching code for: all references to a symbol global definitions functions called by a function functions calling a function text string regular expression pattern a file files including a file

How do I transmit a single hexadecimal value serial data in PuTTY using an Alt code?

I am trying to sent a specific hexadecimal value across a serial COM port using PuTTY. Specifically, I want to send the hex codes 9C, B6, FC, and 8B. I have looked up the Alt codes for these and they are 156, 182, 252, and 139 respectively. However, whenever I input the Alt codes, a preceding hex value of C2 is sent before 9C, B6, and 8B so the values that are sent are C2 9C, C2 B6, and C2 8B. The value for FC is changed to C3 FC. Why are these values being placed before the hex value and why is FC being changed altogether? To me, it seems like there is a problem internally converting the Alt code to hex. Is there a way to directly input hex values without using Alt codes in PuTTY? Answer What you're seeing is just ordinary text character set conversion. As far as PuTTY is concerned, you are typing (and reading) text , not raw binary data, therefore it has to convert the text to bytes in whatever configured character set before sending it over the wire. In other words, when y...

linux - CentOs 7.1 - Install Tomcat 8

I am using this tutorial as a setup reference to getting a Tomcat 8 running on CentOs 7.1 , but after typing: [root@localhost tomcat]# sudo systemctl start tomcat I get the error: Job for tomcat.service failed. See 'systemctl status tomcat.service' and 'journalctl -xn' for details. systemctl status tomcat.service prints the following: [root@localhost tomcat]# systemctl status tomcat.service tomcat.service - Apache Tomcat Web Application Container Loaded: loaded (/etc/systemd/system/tomcat.service; disabled) Active: failed (Result: exit-code) since Wed 2015-11-25 16:54:33 CET; 1min 19s ago Process: 45873 ExecStart=/opt/tomcat/bin/startup.sh (code=exited, status=203/EXEC) Nov 25 16:54:33 localhost.localdomain systemd[1]: Starting Apache Tomcat Web Application Container... Nov 25 16:54:33 localhost.localdomain systemd[1]: tomcat.service: control process exited, code=exited status=203 Nov 25 16:54:33 localhost.localdomain systemd[1]: Failed to start Apache Tomcat Web App...