Hey guys, I wanted to ask you how you manage your gpg keys? Having them in plaintext all the time on my hard drive feels unsecure.

I have my ssh keys in a password manager (KeePassXC) that only exposes them to the keyagend, when unlocked. Do you know if something like that exists for pgp too?

  • Flax@feddit.uk
    link
    fedilink
    English
    arrow-up
    3
    ·
    10 hours ago

    Depends on how strong your password is and the environment you are entering the password in

    • hummingbird@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      36 minutes ago

      It differs between software vendors and versions. For example, if you’re using a recent version of gnupg, your key is most likely stored using openpgp-s2k3-ocb-aes. Use that as a starting point to find more information on how good the protection is. I personally would rate it a fair bit lower compared to the key derivation methods used in keepass which focus more on brute force resistance.