From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from lists.gentoo.org (pigeon.gentoo.org [208.92.234.80]) by finch.gentoo.org (Postfix) with ESMTP id E570B1392EF for ; Mon, 7 Jul 2014 00:33:24 +0000 (UTC) Received: from pigeon.gentoo.org (localhost [127.0.0.1]) by pigeon.gentoo.org (Postfix) with SMTP id ACBE1E087B; Mon, 7 Jul 2014 00:33:19 +0000 (UTC) Received: from mail-ig0-f180.google.com (mail-ig0-f180.google.com [209.85.213.180]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by pigeon.gentoo.org (Postfix) with ESMTPS id B3234E0863 for ; Mon, 7 Jul 2014 00:33:18 +0000 (UTC) Received: by mail-ig0-f180.google.com with SMTP id h18so3816878igc.1 for ; Sun, 06 Jul 2014 17:33:18 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :content-type; bh=z/9U1E7QEOm5YsrAjpXLN9jNVdCf8/0KX5zR2/y+ANA=; b=XT3sy6cltV1PuCXnXiPmsFT/SxiSLGe8xYpPyyycDwOST2XJZERw2bbTtAEosSlCg2 /t3YIALsBq2wPE8gxBKsyXFJykgYPlDmKwO1oMygwR3JvX/PhfQ5myk7BthVAH0NVKo3 3u+iwCNJoIVH/ZZ3W8TK1hBZzVP2EtVauWBRsC5l2VDRVfG0PBp5X9Dh+lq/PdDR8g8K yxSuzgEChzAWJ90VLWckJUzqrPXedw8mbPfymwqXJ18GByjl/rnb2ucwhBGVRx6PnBIe WJu0CbbhNr72hWPr5g3Ep9iwGhY/rL79DjTqpjaC5Iovj6CBdGA9bX2ZSIdspU1v64z0 GaGA== Precedence: bulk List-Post: List-Help: List-Unsubscribe: List-Subscribe: List-Id: Gentoo Linux mail X-BeenThere: gentoo-user@lists.gentoo.org Reply-to: gentoo-user@lists.gentoo.org MIME-Version: 1.0 X-Received: by 10.50.122.100 with SMTP id lr4mr19385235igb.5.1404693197961; Sun, 06 Jul 2014 17:33:17 -0700 (PDT) Received: by 10.42.115.201 with HTTP; Sun, 6 Jul 2014 17:33:17 -0700 (PDT) In-Reply-To: <201407062009.36913.michaelkintzios@gmail.com> References: <201407062009.36913.michaelkintzios@gmail.com> Date: Sun, 6 Jul 2014 17:33:17 -0700 Message-ID: Subject: Re: [gentoo-user] How does ssh know to use "pinentry"? From: Chris Stankevitz To: "gentoo-user@lists.gentoo.org" Content-Type: text/plain; charset=UTF-8 X-Archives-Salt: 7045e3c3-6676-4c99-a4db-117f2865d857 X-Archives-Hash: 0dfeae9b0f203f97f609a1f3693f6185 On Sun, Jul 6, 2014 at 12:09 PM, Mick wrote: > I think that the idea of keeping your passphrase in the clipboard is frowned > upon for security reasons. Not only because of any potential memory leaks, > but because you may inadvertently paste it in GUI fields/areas you were not > meant to Mick, Thank you. I too have been concerned about this. I've also been concerned about "memory leaks". FYI one cute feature of keepass is that it clears the clipboard 20 seconds after you copy your password to it. Today (2014) I am choosing to use the clipboard/keepass to manage complex/unique passwords. Perhaps in the future (2015) everybody will support something like the Yubikey HW OTP... in which case it won't matter if everyone sees my password! Chris