You are not logged in.

#1 2014-10-22 13:34:50

dsar
Member
From: Saint Petersburg
Registered: 2014-10-09
Posts: 44

handle your private key properly

Hello everyone,

    I am interesting to be a little bit more secure in my life.. I would like to know, if I create a PGP key then is it secure to keep it in my own computer?
What is the correct way to handle your private key and make sure that nobody is going to steal it? And if I do not keep it, and write it to an external disk or somewhere else,
how am I going to decrypt my emails? I will every time load my key from the external disk and doing the same thing every time?
and what if I am online and somebody steal it that moment?

I would appreciate it if I knew how you handle this!
Thank you.

* my question occured by reading GnuPG
** Is there anything similar with the ssh-agent?

Last edited by dsar (2014-10-22 15:17:22)

Offline

#2 2014-10-22 15:20:47

branch
Member
Registered: 2014-03-16
Posts: 209

Re: handle your private key properly

See the GNU Privacy Handbook [1] subsection titled "Protecting your private key".

It boils down to how much inconvenience you can tolerate to protect it. Remember a well protected private key is useless if it is so inconvenient that you never use it.

[1] https://www.gnupg.org/gph/en/manual.html

Offline

#3 2014-10-22 15:22:53

dsar
Member
From: Saint Petersburg
Registered: 2014-10-09
Posts: 44

Re: handle your private key properly

branch wrote:

Remember a well protected private key is useless if it is so inconvenient that you never use it.

That was my main point! Thank you!

Offline

Board footer

Powered by FluxBB