Silk Road forums

Discussion => Security => Topic started by: StiffyAllDay on April 07, 2013, 09:42 pm

Title: Multiple PGP key encryption.
Post by: StiffyAllDay on April 07, 2013, 09:42 pm
Hello all,

Just asking, if I have say 3 items in my cart, and want to encrypt my address and enter that into the box where my address is required, can I use the 3 keys at once to encrypt my address and all the keys can decrypt the gibberish that comes out?

If that don't make sense then just say and I'll try to explain a bit more!

Thanks.
Title: Re: Multiple PGP key encryption.
Post by: SelfSovereignty on April 07, 2013, 09:46 pm
Yes, you can encrypt for 3 people at once and have all 3 be able to decrypt the same message.  It's often used to encrypt outgoing messages to your own key, so that you can read them later on -- personally I find that kind of weakens security, but there have been times I've wished I had done it...
Title: Re: Multiple PGP key encryption.
Post by: StiffyAllDay on April 07, 2013, 09:54 pm
Thanks SS, I never even considered that you could encrypt it with your own key in order to read it back later! Useful to know. Is there evidence of it reducing security or is that just your opinion? I guess due it having to be able to be decrypt-able by 3 different keys will reduce the security.
Title: Re: Multiple PGP key encryption.
Post by: SelfSovereignty on April 07, 2013, 10:02 pm
Oh, I meant reduces security in the sense that if someone wants to read your communications to incriminate you, they now only need to guess your passphrase -- since they'll likely already have access to your computer when they arrest you or something.

It's not a technical concern, just a "but I don't WANT my private key to be able to decrypt this, I know what I'm saying and don't want to be able to recover it," thing.
Title: Re: Multiple PGP key encryption.
Post by: StiffyAllDay on April 07, 2013, 10:05 pm
Ohh, okay :)

I'm with you now! Thanks for clearing that up, if I had the ability to give you karma I would!

Cheers.
Title: Re: Multiple PGP key encryption.
Post by: astor on April 07, 2013, 10:48 pm
Keep in mind that in the default PGP configuration, the recipients can see all the key IDs that you used to encrypt the message.

If you don't want the vendors to know what other vendors you're buying from, read this:

http://dkn255hz262ypmii.onion/index.php?topic=137510.0