image
image

Go Back   macosx.com > Mac Help Forums > Mac OS X System & Mac Software

Reply
 
Thread Tools
  #1  
Old March 30th, 2003, 01:45 AM
michaelsanford's Avatar
Psycholinguist
 
Join Date: Oct 2002
Location: Ottawa/Montrιal
Posts: 2,109
michaelsanford is on a distinguished road
Unhappy Note about PGP 8 keyring security (permissions).

I just did a default installation of PGP 8 for Jaguar, and noticed something rather disturbing. Though it's not really a critical issue, it's something that I think every seriously security-concious PGP user should do something about.

PGPKeys puts your private keyring, by default, in ~/Documents/PGP/ and sets the folder permissions to drwxrwxr-x which essentially means anyone who has access to your system can grab your private keyring, or replace it with a spoofed one! To makes matters worse, if you have symlinks from from your web folder to all over the place (to share movies, photos, whatever), you may have accidentally given web access to it as well.

To rectify this, I changed the folder (put it in ~/) and set the permissions to drwx------ (and also applied it to the key ring files themselves).

Someone with SSH or unchrooted FTP access can see everything if you're not careful

Anyway, it strikes me as pretty silly that the PGP installer doesn't take care of that...I think they're gonna get an email from me tonight.

If I get seriously paranoid, I can always put my private keyring on my USB flash drive (see sig), which actually seems like an ideal place...
__________________
michaelsanford.com • Blog • Twitter • Tumblr • LinkedIn
• iBook G4 1.42 GHz | MacOS X 10.5-current | 1 GB RAM, 100 GB HDD
• iMac G4 TFT 700 MHz | MacOS X 10.3.9 | 768 MB RAM, 40 GB HDD
• AMD Athlon64 3500+ | Slackware 12 (2.6.21.5-smp) | 2 GB RAM, 2•120 GB RAID 1, 2•500 GB RAID 0
Reply With Quote
  #2  
Old March 30th, 2003, 12:38 PM
Giaguara's Avatar
Chmod 760
 
Join Date: Nov 2002
Posts: 7,333
Giaguara is on a distinguished road
Good to know.

I have been using GnuPG since I came to OS X and .. no problems with that.

http://macgpg.sourceforge.net/

__________________
MacBook Pro + Mac mini | Newton 2000 | @Work : Dell D620 & 2x20" + a lot of Macs | Workstation, VC & Fusion
Twenty years from now you will be more disappointed by the things that you didn't do than by the ones you did do.
~ Samuel Clemens | Rants | Photos
Reply With Quote
  #3  
Old March 30th, 2003, 12:50 PM
michaelsanford's Avatar
Psycholinguist
 
Join Date: Oct 2002
Location: Ottawa/Montrιal
Posts: 2,109
michaelsanford is on a distinguished road
Oh yeah GPG's great, I just like PGP for the interface and plugins, I find it marginally simpler to use....
__________________
michaelsanford.com • Blog • Twitter • Tumblr • LinkedIn
• iBook G4 1.42 GHz | MacOS X 10.5-current | 1 GB RAM, 100 GB HDD
• iMac G4 TFT 700 MHz | MacOS X 10.3.9 | 768 MB RAM, 40 GB HDD
• AMD Athlon64 3500+ | Slackware 12 (2.6.21.5-smp) | 2 GB RAM, 2•120 GB RAID 1, 2•500 GB RAID 0
Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
[FAQ] - PGP 8.0 Keychain vulnerability on Mac OS X michaelsanford HOWTO & FAQs 1 March 31st, 2003 08:45 PM
severe security issue with Mac OS X 10.2 profx Mac OS X System & Mac Software 15 September 16th, 2002 05:42 AM
UNIX related things... (tr, cut, awk, and permissions) simX Apple News, Rumors & Discussion 5 December 19th, 2001 02:33 AM
File permissions and the drop box. ericmurphy Apple News, Rumors & Discussion 2 July 3rd, 2001 08:55 AM


All times are GMT -5. The time now is 01:05 AM.


Mac Support® Version 3.7.0 Beta 5
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.1.0
Copyright 2000-2008 DigitalCrowd, Inc.