From mboxrd@z Thu Jan 1 00:00:00 1970 X-Msuck: nntp://news.gmane.io/gmane.emacs.gnus.general/53950 Path: main.gmane.org!not-for-mail From: Simon Josefsson Newsgroups: gmane.emacs.gnus.general Subject: Re: Entering passphrase twice when sending PGP signed message Date: Sun, 14 Sep 2003 02:41:52 +0200 Sender: ding-owner@lists.math.uh.edu Message-ID: References: NNTP-Posting-Host: deer.gmane.org Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii X-Trace: sea.gmane.org 1063500153 30606 80.91.224.253 (14 Sep 2003 00:42:33 GMT) X-Complaints-To: usenet@sea.gmane.org NNTP-Posting-Date: Sun, 14 Sep 2003 00:42:33 +0000 (UTC) Cc: ding@gnus.org Original-X-From: ding-owner+M2490@lists.math.uh.edu Sun Sep 14 02:42:31 2003 Return-path: Original-Received: from malifon.math.uh.edu ([129.7.128.13]) by deer.gmane.org with esmtp (Exim 3.35 #1 (Debian)) id 19yKyF-0001eq-00 for ; Sun, 14 Sep 2003 02:42:31 +0200 Original-Received: from localhost ([127.0.0.1] helo=lists.math.uh.edu) by malifon.math.uh.edu with smtp (Exim 3.20 #1) id 19yKxp-0001Ga-00; Sat, 13 Sep 2003 19:42:05 -0500 Original-Received: from sclp3.sclp.com ([64.157.176.121]) by malifon.math.uh.edu with smtp (Exim 3.20 #1) id 19yKxg-0001GS-00 for ding@lists.math.uh.edu; Sat, 13 Sep 2003 19:41:57 -0500 Original-Received: (qmail 78231 invoked by alias); 14 Sep 2003 00:41:56 -0000 Original-Received: (qmail 78225 invoked from network); 14 Sep 2003 00:41:56 -0000 Original-Received: from 178.230.13.217.in-addr.dgcsystems.net (HELO yxa.extundo.com) (217.13.230.178) by sclp3.sclp.com with SMTP; 14 Sep 2003 00:41:56 -0000 Original-Received: from latte.josefsson.org (yxa.extundo.com [217.13.230.178]) (authenticated bits=0) by yxa.extundo.com (8.12.9/8.12.9) with ESMTP id h8E0fqdk004043 (version=TLSv1/SSLv3 cipher=EDH-RSA-DES-CBC3-SHA bits=168 verify=FAIL); Sun, 14 Sep 2003 02:41:54 +0200 Original-To: Hrvoje Niksic Mail-Copies-To: nobody X-Payment: hashcash 1.2 0:030914:hniksic@xemacs.org:cdbf804eb643407b X-Hashcash: 0:030914:hniksic@xemacs.org:cdbf804eb643407b X-Payment: hashcash 1.2 0:030914:ding@gnus.org:ac851eb554f9f74a X-Hashcash: 0:030914:ding@gnus.org:ac851eb554f9f74a In-Reply-To: (Hrvoje Niksic's message of "Sun, 14 Sep 2003 01:20:16 +0200") User-Agent: Gnus/5.1003 (Gnus v5.10.3) Emacs/21.3.50 (gnu/linux) Precedence: bulk Xref: main.gmane.org gmane.emacs.gnus.general:53950 X-Report-Spam: http://spam.gmane.org/gmane.emacs.gnus.general:53950 Hrvoje Niksic writes: > How about remembering the passphrase and reusing it the second time? > The passphrase would be forgotten the moment the mail sending process > is finished. At first that sounds like a violation of passphrase > privacy, but think about it: as long as the string is not copied > around, it's no more dangerous to use it twice and delete it than to > prompt for it twice, deleting it each time around. This is supposed to work by default, but if you have multiple PGP identities, there is a known problem. For me, the passphrase is cached so everything is decrypted automatically, but for signing I have to enter it (twice). I think pgg guess wrong about what id to cache the passphrase under, so it doesn't find the passphrase when pgg need it the next time.