4 ms·
I guess I'm a pretty big noob, but why do people recommend so strongly on password protecting your private key? Losing it pretty much dooms you whether or not i
by windsurfer 10y ago
I guess I'm a pretty big noob, but why do people recommend so strongly on password protecting your private key? Losing it pretty much dooms you whether or not it's password protected. It might get you a few hours or so to react and invalidate the public key, I guess...
- ryanlol 10y agoIf you've got a good password on your key, then nobody will be able to use it in years. It most certainly helps.
- windsurfer 10y agoYears? How long a password would you need to make GPU cracking take years?
- ryanlol 10y agoA very short one. Reasonable 10+ character passwords should remain out of reach for years. Also, AFAIK there doesn't currently exist any very effective GPU cracking software for SSH passphrases.
- chrisseaton 10y agoI went to lookup the algorithm GPG uses to encrypt private keys, to help answer the original question, but couldn't seem to find that information anywhere. Do you know what it is?
- windsurfer 10y agoAccording to a quick stack exchange search, OpenSSL uses 3DES for encryption of private keys.
- chrisseaton 10y agoYou're already given your own concrete time estimate - 'hours' - how did you work that out?
- windsurfer 10y agoAn old article I read about password cracking using EC2 while back... let me look it up.