GnuPG cannot know if is runs in a "secure" environment (Re: standard comment)

Bernhard Reiter via Gnupg-users <[email protected]> Fri, 29 May 2026 09:10:26 +0200
Newsgroups gmane.comp.encryption.gpg.user
Message-ID <[email protected]>
--===============5705833905026031322==
Content-Type: multipart/signed;
  boundary="nextPart3256906.qHUEMGdtsv";
  protocol="application/pgp-signature";
  micalg=pgp-sha1
Content-Transfer-Encoding: 7bit

--nextPart3256906.qHUEMGdtsv
Content-Type: text/plain;
  charset="utf-8"
Content-Transfer-Encoding: quoted-printable
Content-Disposition: inline

Hi,

Am Montag 25 Mai 2026 06:36:55 schrieb marqueandreprisal--- via Gnupg-users:
> How would this fine community recommend to make a standardized comment
> about keys being used in unsecure environments. For example buying an
> android=E2=84=A2 off of the shelf and using keys with GnuPG Termux or Open
> Keychain is not sure because androids often have swap files which may be
> setup to dump memory and snag the private key.

as far as I can say a crypto component cannot tell if it is run
on an "unsecure" environment or not.

So even if GnuPG or Openkeychain wanted to record this, they would not be a=
ble=20
to find out about this with reasonable certainty.

Consider the example that the software is running in a virtualized environm=
ent=20
like qemu, which is "unsecure" in the sense that qemu can observe everythin=
g.
As qemu can "simulate" everything, it is not really possible to detect the=
=20
fact.

On the other hand, a Android system maybe run air-gapped in a confined plac=
e,=20
with a self build kernel and everything, which would make it quite "secure"=
=2E=20
So detecting that termux was used would not make a key pair "unsecure" alon=
e.

Regards,
Bernhard


=2D-=20
https://intevation.de/~bernhard =C2=A0 +49 541 33 508 3-3
Intevation GmbH, Osnabr=C3=BCck, DE; Amtsgericht Osnabr=C3=BCck, HRB 18998
Gesch=C3=A4ftsf=C3=BChrer: Frank Koormann, Bernhard Reiter

--nextPart3256906.qHUEMGdtsv
Content-Type: application/pgp-signature; name=signature.asc 
Content-Description: This is a digitally signed message part.

-----BEGIN PGP SIGNATURE-----

iQGzBAABCgAdFiEEvdlX+cT+D9xYPc1tK3ujv5vDpVQFAmoZO+IACgkQK3ujv5vD
pVS26wv+M+W+q1LBsE1jjlYvmXSMKLqckUGgpQMffxI10IlpeL134RkZZ7cOG7Am
8ZEmpF+YnbnQ1U0PLtFx2r+S/toiUoBvGtqg1S5x28cH9JwXfQTJ5UhLkfvoijdF
sEIn/XcvH3Bp+sYM7FEMOArooMWuaWwbuh4dpQsSgY3MPo7HgmEf4y5EV+mqHsw9
1AkbsyuKSuqLvDE8deNBU7z3Ba2Nchqt6yh42NwH9k75fyMi7A6FBNtURzEBz5NB
Pq52UFZio/25z2QXUXKkOYvPLN6W96auWGGVqDaBM3a+AdLqajquaeWIAzqpIbLV
adtz60rsEY1TFOgzLtS7AzPCaOyTa5jB7oVwd1PH1iH/DVOBU6UgiZEG7Zq+l9Ih
91viWogom+tnPziF7xEZSLFoynenWojOJwUVLyfn2DV2wwd+plnYs4Mugji+JLsP
FrTjP3Gh4Nf4bZB2G0z/Uy484g4Kl2z4me9F3XhxlrkLOlOEcdn0NKath73NGw0R
MaEkC/LM
=jpx4
-----END PGP SIGNATURE-----

--nextPart3256906.qHUEMGdtsv--


--===============5705833905026031322==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Gnupg-users mailing list
[email protected]
https://lists.gnupg.org/mailman/listinfo/gnupg-users

--===============5705833905026031322==--