In case you use OpenPGP on a smartphone ...

Stefan Claas sac at
Fri Aug 14 14:16:52 CEST 2020

Stefan Claas wrote:
> Andrew Gallagher wrote:

> > No, you should not stop using encryption software on online devices.
> > That would be insane. We should be adding more encryption at multiple
> > levels, so that compromise of one layer of encryption does not mean a
> > compromise of the entire system. Defence in depth is the only long-term
> > sustainable strategy.
> While I personally stopped using online encryption, long ago, after my
> Linux system was hacked, I like to mention (in case people do not know)
> that YubiKeys and Nitrokeys allow also login-in protection via 2FA and
> that than sudo usage requires also tapping on the YubiKey, besides pw
> usage. Not sure if it is the same procedure with a Nitrokey.

