Why trust gpg4win?
Jan
takethebus at gmx.de
Wed Sep 11 11:01:26 CEST 2013
On 10/09/2013 15:18, NdK wrote:
>>> You'd be exposed nearly to the same attack vectors. Plus some more (the
>>> ones that handle the extra layer), so you'd have to check more code.
>> So what about using that free USB stack for AVR's to implement a flash
>> device? You would be able to audit about everything; flylogic even has
>> these nice pictures of the ATmega88 masks...
>Sorry, I don't follow your reasoning here.
>Pete proposed to use an USB-to-Serial interface to avoid attacks against
>the USB stack on the PC. Why should an AVR be used to implement a flash
>device?
Maybe Pete meant such an USB-to-Serial interface
http://www.robotsimple.com/Computer_Interface/USB_to_Serial_Adapter ?
Nevertheless this seems quite tricky to handel. Is it better to use a CD-RW
to transfer data between an offline and an online PC than to use an ordinary
USB stick?
Which other medium might be good?
Kind regards,
Jan
More information about the Gnupg-users
mailing list