Hacker News new | ask | show | jobs
by upofadown 1760 days ago
This seems to be primarily for forwarding files. It is unlikely that the users would want to get rid of the files after transfer. Any attack intense enough to get access to the passphrase for the secret key (keylogger) will pretty much for sure give access to the files on the system involved at the time of attack (including insecurely deleted files) and any files that exist on the system going forward.

The whole thing is generally more secure then many of these file transfer things due to the use of the passphrase. The idea of strongly protecting the secret key against local attacks is a PGPism that tends to be forgotten these days.

1 comments

Yes, this will be used in our organization to transfer various documents (mainly pdf/word files) that contain sensitive data (i.e medical conditions of colleagues).