-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
jbn10161 wrote:
> 1. From the article: "Most encryption products now offer
> multiple-key disk encryption, a concept pioneered by FIPR Chair
> Professor Ross Anderson, along with Adi Shamir and Roger Needham in
> their paper on "The Steganographic File System," which was written in
> response to early key escrow moves. Such systems let a user create
> multiple encrypted partitions, without an outsider knowing how many."
> Does GnuPG implement this?
GnuPG is an open-source implementation of RFC2440. That's all.
GnuPG has absolutely nothing to do with filesystems.
The report is in error when it says "most encryption products now
offer...". This is still very much experimental. TrueCrypt does
something similar to this, but I can't think of any other really
reputable systems that do.
> moves much faster than law. Access to keys was first mooted (recently)
> in the USA in 1993, and in the UK by DTI minister Ian Taylor in
> 1996." How was access to keys mooted in the US?
No idea. This is a claim I'd like to see backed up, given that keys can
be subpoenaed, or can be obtained surreptitiously via a combination of
keyloggers and sneak-and-peek warrants. Key access in the US is
definitely not a moot point.
> 3. The article's description of a duress key as something that will
> decrypt file A while destroying file B is intriguing. I have seen hot
> keys on programs that will destroy an encrypted and mounted volume,
> but I have not seen the type of double-duty duress encryption key
> described in the article. What programs have this?
Totally unknown. Keep in mind that any attempt to wipe data from a
drive which does not physically obliterate the disk platters is risky at
best. I am deeply skeptical of so-called "disk cleaners".
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (Darwin)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org
iQEcBAEBCgAGBQJFBbmWAAoJELcA9IL+r4EJ4agIALvg70v3/f6umUmPglbMuRxZ
0fpacnACJ+ir2o7mmS8ZJyScE+o7X9lqH2AC39q4DmmDGUDeQM1WWNKrtkT7hVH8
uIuFFJ46IMsycmWZB85qf4S8XoSMKwXwXR9Tftrrh67YhpGUBfuqO/w9BIhfXn6s
3VYQIS5NG92hs4Cc7wMB97hnsoMWUHULpjVQvjUsbURNoQv2S9R3VbHxQhIJaOJX
diEs074CD+Yt3/JDeARmPj7ZjoTX4C6L9DTSb8kDE0snH2TYnLZEDDeEvDdjaB6A
EkPaGBTfHeaCLbmw63Tpc87Zsv8XGG4USZ241aJpgtXwUhm+ONuzHfmNwaPkzVM=
=gW5c
-----END PGP SIGNATURE-----
.