3 ms·
If the encrypted private-key is stolen, then it can be stored on a powerful computer and brute-force attacks can be applied on it. Even if symmetric encryption
by dopkew 16y ago
If the encrypted private-key is stolen, then it can be stored on a powerful computer and brute-force attacks can be applied on it. Even if symmetric encryption is used to encrypt the private-key ( which makes straight-on brute-force attacks unfeasible), if the user uses an easy passphrase to encrypt the private-key, then the private-key can be compromised.
From Wikipedia:
In the case of an offline attack where the attacker has access to the encrypted material, he can try key combinations at his leisure without the risk of discovery or interference. However database and directory administrators can take countermeasures against online attacks, for example by limiting the number of attempts that a password can be tried, by introducing time delays between successive attempts and locking accounts out after unsuccessful logon attempts. Website administrators may prevent a particular IP address from trying more than a predetermined number of password attempts against any account on the site.