Trying Like Hell To Defeat The Purpose Of Encrypting Something In The First Place
August 8, 2008 6:04 PM
Subscribe
How weak is it smart to allow my GPG key passphrase to get?
When selecting a passphrase for my GPG key, is it important that it be maximally obfuscated (a random string of alphanumerics and special characters that is $MAX_STRING_LEN long)? Would it be acceptable to use a partially-obfuscated string that's at least memorizable? Would it be considered beyond the pale of idiocy to incorporate a word in the dictionary in the keyphrase?
Ideally, I'd like to be able to type the passphrase in from memory, and (for me) that is easiest done if – while incorporating special chars, numbers, and caps variations – is also at least based on an English word or phrase. Is that erect-a-monument-to-it stupid?
posted by ChasFile to computers & internet (8 comments total)
2 users marked this as a favorite
posted by idiotfactory at 6:23 PM on August 8, 2008