Re: [Tails-dev] Security implications of storing secrets saf…

Delete this message

Reply to this message
Author: sajolida
Date:  
To: The Tails public development discussion list
Subject: Re: [Tails-dev] Security implications of storing secrets safe password in persistent storage
payback-prudishly via Tails-dev:
> Hi devs,


Hi, welcome to tails-dev!

> Thanks heaps for Tails OS!


Glad it's useful :)

> Just wondering what the security implications are of keeping the gnome
> secrets passphrase within the encrypted persistent storage, or
> alternatively using the same passphrase for the persistent storage and
> gnome secrets, to avoid having to remember multiple passphrases?
> https://tails.net/doc/encryption_and_privacy/manage_passwords/
> index.en.html <https://tails.net/doc/encryption_and_privacy/
> manage_passwords/index.en.html> talks about making sure to remember the
> secrets passphrase, but is silent about both those options

Good question. I create a GitLab issue to track this with some initial
thoughts within the limits of my technical knowledge:

https://gitlab.tails.boum.org/tails/tails/-/work_items/21506

Feel free to continue the discuss here, for folks who don't have a
GitLab account. I'll summary and crosspost.

--
sajolida
The Tor Project — UX Designer