USB vs Smart Card?

Moritz Schulte mo at g10code.com
Fri Dec 29 11:06:21 CET 2006


> Can I use a USB instead of a Smart Card?

Without further context this question does not make too much sense.  USB
sticks (i guess that is what you mean) are completely different from
smartcards when it comes to security solutions.

Surely it is possible to e.g. store secret keys on a USB stick and thus
enforce the use of that device for secret operations.  But what USB
sticks do not provide you with is encapsulation of secret operations.
Means: while it is possible to copy the secret key from your USB stick
to the computer to which the device is connected, crypto smartcards
(e.g. the OpenPGP smartcard) do never give out the secret key.  The
decrypt/sign operations are implemented in the card itself, access is
protected with PINs.

Moritz





More information about the Gnupg-users mailing list