Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Even if they have a passphrase it has to be strong enough to withstand brute force for months. If you're not smart enough to keep the private key separate from the crap you're trying to protect, why should I think you're smart enough to ensure your passphrase is good enough?


why should I think you're smart enough to ensure your passphrase is good enough

Key strengthening.


OpenSSL doesn't use key strengthening on password protected RSA keys. GPG does, but I don't know how much it does by default.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: