View Single Post
  #1  
Old March 30th, 2003, 02:45 AM
michaelsanford's Avatar
michaelsanford michaelsanford is offline
Psycholinguist
 
Join Date: Oct 2002
Location: Ottawa/Montrιal
Posts: 2,174
Thanks: 0
Thanked 0 Times in 0 Posts
michaelsanford is on a distinguished road
Unhappy Note about PGP 8 keyring security (permissions).

I just did a default installation of PGP 8 for Jaguar, and noticed something rather disturbing. Though it's not really a critical issue, it's something that I think every seriously security-concious PGP user should do something about.

PGPKeys puts your private keyring, by default, in ~/Documents/PGP/ and sets the folder permissions to drwxrwxr-x which essentially means anyone who has access to your system can grab your private keyring, or replace it with a spoofed one! To makes matters worse, if you have symlinks from from your web folder to all over the place (to share movies, photos, whatever), you may have accidentally given web access to it as well.

To rectify this, I changed the folder (put it in ~/) and set the permissions to drwx------ (and also applied it to the key ring files themselves).

Someone with SSH or unchrooted FTP access can see everything if you're not careful

Anyway, it strikes me as pretty silly that the PGP installer doesn't take care of that...I think they're gonna get an email from me tonight.

If I get seriously paranoid, I can always put my private keyring on my USB flash drive (see sig), which actually seems like an ideal place...
__________________
michaelsanford.com • Blog • Twitter • Tumblr • LinkedIn
• iMac Aluminum 24" |
MacOS X 10.5-current | 3.06 GHz Intel Core Duo | 4 GB RAM | 1 TB HDD
• iBook G4 1.42 GHz | MacOS X 10.5-current | 1 GB RAM, 100 GB HDD
• AMD Athlon64 3500+ | Slackware 12 (2.6.21.5-smp) | 2 GB RAM, 2•120 GB RAID 1, 2•500 GB RAID 0
Reply With Quote