Index | Thread | Search

From:
Stuart Henderson <stu@spacehopper.org>
Subject:
Re: flare messenger needs Secret Service provider
To:
"sysop@ubik.com.de" <sysop@ubik.com.de>
Cc:
Mikolaj Kucharski <mikolaj@kucharski.name>, ports@openbsd.org, owner-ports@openbsd.org
Date:
Sat, 14 Feb 2026 18:42:40 +0000

Download raw body.

Thread
On 2026/02/14 17:13, sysop@ubik.com.de wrote:
> Without looking at the code, the actual risks seem (imo) low, but I
> don't know your threat model.

if some random process run by your uid is not allowed to read the
password without confirmation, it should not be able to read an otp key
either. (*possibly* an otp calculated value might be ok, but the key is
*at least* as sensitive as a password, probably more so).