Hey guys, I wanted to ask you how you manage your gpg keys? Having them in plaintext all the time on my hard drive feels unsecure.

I have my ssh keys in a password manager (KeePassXC) that only exposes them to the keyagend, when unlocked. Do you know if something like that exists for pgp too?

you are viewing a single comment's thread
view the rest of the comments
[–] 3 points 8 months ago (1 child)

Depends on how strong your password is and the environment you are entering the password in

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 8 months ago

    It differs between software vendors and versions. For example, if you're using a recent version of gnupg, your key is most likely stored using openpgp-s2k3-ocb-aes. Use that as a starting point to find more information on how good the protection is. I personally would rate it a fair bit lower compared to the key derivation methods used in keepass which focus more on brute force resistance.

  • source
  • parent