kdewallet and kmail

Derek Broughton news at pointerstop.ca
Fri Feb 2 15:54:17 UTC 2007


Art Alexion wrote:

> As I said, I like it.  Less for security than for a repository for
> remembering
> passwords.  I think there is something inherently insecure about storing a
> variety of passwords under a single password.  To the extent that a
> variety of passwords means that if one password is breached, the others
> remain secure, if your master password is breached, all of your other
> passwords are exposed.

Absolutely.  90% of the passwords we have are for websites that insisted we
have a password, but didn't let us choose our own, so those go in kwallet.

> That's theoretical when applied to me, and I suspect most other ordinary
> individuals.  Security is not that big a deal, and I can't remember dozens
> of
> different ones in my head.  PGP encryption can effectively hide what is
> really private, and kwallet doesn't store that password.

I confess, I have one pgp passphrase manually stored in the wallet :-)  
-- 
derek





More information about the kubuntu-users mailing list