emacs-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Fix needed for communication with gpg-agent


From: Chong Yidong
Subject: Re: Fix needed for communication with gpg-agent
Date: Wed, 21 Feb 2007 07:04:32 -0500
User-agent: Gnus/5.11 (Gnus v5.11) Emacs/22.0.93 (gnu/linux)

Richard Stallman <address@hidden> writes:

> I think he could also walk up to your terminal after you have entered
> the passphrase, and get it out of data remaining in Emacs.
>
> In the discussion when this was raised, people seemed to agree
> it was a problem we should fix.  And the only fix was to avoid
> storing passphrases in Emacs.

There is more than one way to fix that.

Since no one seems to have an idea of how to handle the
console/pinentry case, let's just disable password caching on text
terminals, and disabling use of gpg-agent on text terminals, by
default.  We can suggest a workaround in the PGG manual, and tell
people to enter a passphrase into pinentry before starting Emacs, if
they want to use PGG with gpg-agent on a text terminal.




reply via email to

[Prev in Thread] Current Thread [Next in Thread]