Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add --no-symkey-cache? #2

Open
otto-dev opened this issue Oct 30, 2019 · 2 comments · May be fixed by #3
Open

Add --no-symkey-cache? #2

otto-dev opened this issue Oct 30, 2019 · 2 comments · May be fixed by #3

Comments

@otto-dev
Copy link

otto-dev commented Oct 30, 2019

From the docs

--symmetric [...] gpg caches the passphrase used for symmetric encryption so that a decrypt operation may not require that the user needs to enter the passphrase. The option --no-symkey-cache can be used to disable this feature.

Is it just me, or is that a rather ridiculous default? Meaning, that by default anyone with access to the shell can decrypt the file without knowing the passphrase while the password is still in cache from the encryption process.

Can be "fixed" by adding --no-symkey-cache

@Slamdunk Slamdunk linked a pull request Dec 30, 2020 that will close this issue
@Slamdunk
Copy link

Indeed, I've opened a PR

@deepsynergy
Copy link

Is this a joke? Caching passphrases by default in a security software? This default behavior should be removed immediately.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants