security-misc icon indicating copy to clipboard operation
security-misc copied to clipboard

improve GnuPG configuration file `/etc/skel/.gnupg/gpg.conf`

Open adrelanos opened this issue 9 months ago • 10 comments

Stronger ciphers?

Any other hardening suggestions?

https://github.com/Kicksecure/security-misc/blob/master/etc/skel/.gnupg/gpg.conf

https://forums.whonix.org/t/anon-gpg-tweaks-gpg-conf-enhancements-duraconf-a-collection-of-hardened-configuration-files/5378

https://www.kicksecure.com/wiki/Air_Gapped_OpenPGP_Key

https://www.kicksecure.com/wiki/OpenPGP

adrelanos avatar May 13 '24 17:05 adrelanos

This should not be too hard. Just choose the one that keeps winning the cipher competitions.

Also, we should make post quantum options the default as soon as possible, for the asymmetric stuff I mean.

Reasonable path for the future is follow this draft really closely.

There are individual post-quantom implementations, but these are not standardized. We should just follow closely the developments in standardization of this. Many big boy projects are already sponsoring the development of such standards. These will be available in the wild. We just want to be ahead of the curve to adapt. Not to mention, the other side should also support these technologies for them to work as intended.

monsieuremre avatar May 20 '24 10:05 monsieuremre

Unless using live mode, writing to RAM is too difficult for users.

/tmp isn't guaranteeing that nothing is written to the disk. (Swap, crash dumps. This goes into the topic of anti-forensics. In short: forget about it and use live mode.)

But what is the point of writing to RAM anyhow in this context? The private key needs to be stored persistently somewhere anyhow.

adrelanos avatar May 28 '24 12:05 adrelanos

Another hardend GnuPG configuration:

  • https://gist.github.com/sebmellen/b0d0424caefa1221cbe4d9aaf2172d2c

ben-grande avatar Jun 12 '24 10:06 ben-grande

Thats many years old and wonder if key size beyond 4096 are really more secure at this point?

  1. Many years old and still newer than the currently used gpg.conf.
  2. I didn't say to trust everything in that file, it has outdated settings, yes, but it has many valuable ones.

ben-grande avatar Jul 01 '24 06:07 ben-grande