duplicity-talk
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Duplicity-talk] Different session key for each backup volume?


From: Christopher Kunz
Subject: Re: [Duplicity-talk] Different session key for each backup volume?
Date: Thu, 23 Jun 2011 13:31:38 +0200
User-agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.6; de; rv:1.9.2.17) Gecko/20110414 Thunderbird/3.1.10

Am 23.06.11 11:14, schrieb Chris Poole:
> Does gpg use a different session key for each volume as Duplicity produces 
> them?
> 
> i.e., if an attacker somehow learns the session key for one backup
> volume, only that volume is compromised?
> 
> 
> Thanks!
No. AFAIK, GPG is strictly asymmetric and does not use session keying at
all (because it is not aware of the concept of sessions).

However, how would an attacker learn the key for a backup volume?
Encryption is done on the client and no key ever passes over the network.

If your client is compromised, so is your backup.

Gruß,

--ck

-- 
Filoo GmbH
Christopher Kunz, Geschäftsführer

E-Mail: address@hidden
Tel.: (+49) 0 52 48 / 1 89 84 -11
Fax: (+49) 0 52 48 / 1 89 84 -20

Please sign & encrypt mail wherever possible, my key:
C882 8ED1 7DD1 9011 C088 EA50 5CFA 2EEB 397A CAC1

[Achtung, neue Firmenadresse!]
Moltkestraße 25a
33330 Gütersloh

HRB4355, AG Gütersloh
Geschäftsführer: S.Grewing, J.Rehpöhler, C.Kunz

Folgen Sie uns auf Twitter: http://twitter.com/filoogmbh



reply via email to

[Prev in Thread] Current Thread [Next in Thread]