Skip to main content

You are not logged in. Your edit will be placed in a queue until it is peer reviewed.

We welcome edits that make the post easier to understand and more valuable for readers. Because community members review edits, please try to make the post substantially better than how you found it, for example, by fixing grammar or adding additional resources and hyperlinks.

4
  • en.wikipedia.org/wiki/… and more specifically en.wikipedia.org/wiki/OCB_mode are relatively recent advances that provide more robust integrity protection against possible tampering of your data than the standard-OpenPGP MDC (Manipulation Detection Code), but for data you don't exchange with other people/systems (and I sure hope you aren't sending your password file to other people!) this is probably unnecessary. If you want to go into this in more detail, security.SX is probably more suitable. ... Commented Mar 4 at 0:58
  • ... Note this is independent of the keypair(s). You can use AEAD/OCB on any of RSA DSA/EG or ECC keypairs, and you can use not-AEAD/OCB on any of them. Ed25519 cannot encrypt, but is usually used with a cv25519 subkey; as long as your systems (all) support these, they are considered quite secure. Commented Mar 4 at 1:03
  • Thanks for the hints. I'll ask at security.SX additionally as you advised. Commented Mar 4 at 6:27
  • 1
    A nice answer was given there: security.stackexchange.com/questions/275883/… Commented Mar 5 at 13:24