Follow

Just a question to the devs who make password wallets etc using GPG: Why do you tell the user, they got only 3 attempts at entering their private key's password?

They don't. They have infinite attempts because they own the key file. I've seen this in and now.

@cweickhmann If users use physical token for GPG keys such as #gnuk token (or anything similar implementing #openpgpcard standard) then they really have only 3 attempts. After 3 wrong attempts token is semi locked and needs Admin PIN to unlock. After 3 wrong admin PIN attempts private key is erased.

@stikonas That is right, but the password manager or the key manager should expose this property.

Sign in to participate in the conversation
Qoto Mastodon

QOTO: Question Others to Teach Ourselves
An inclusive, Academic Freedom, instance
All cultures welcome.
Hate speech and harassment strictly forbidden.