|
@@ -143,7 +143,7 @@ This system tries to block port scanners. Any other system trying to scan for op
|
143
|
143
|
* Should I upload my GPG keys to keybase.io?
|
144
|
144
|
It's not recommended unless there exists some compelling reason for you to be on there. That site asks users to upload the *private keys*, and even if the keys are client side encrypted with a passphrase there's always the chance that there will be a data leak in future and letter agencies will then have a full time opportunity to crack the passphrases.
|
145
|
145
|
|
146
|
|
-Saying something resembling /"only noobs will use crackable private key passphrases"/ isn't good enough. A passphrase should not be considered to be a substitute for a private key.
|
|
146
|
+Saying something resembling "/only noobs will use crackable private key passphrases/" isn't good enough. A passphrase should not be considered to be a substitute for a private key.
|
147
|
147
|
* Keys and emails should not be stored on servers. Why do you do that?
|
148
|
148
|
Ordinarily this is good advice. However, the threat model for a device in your home is different from the one for a generic server in a massive warehouse. Compare and contrast:
|
149
|
149
|
|