Recommended by 1 curator | |
but where to store your password 😅 to encrypt the master key lol … but interesting, fyi this is done with age file encryption https://github.com/FiloSottile/age Age encryption seems to have become a new standard. The master key should be -- or protected by -- a hardware/software key combination, so eg a password + fido stick. (At least two sticks, they seem to "age" too.) But so why is this better than just keeping a secret seed phrase? Also wouldn't the master key password at least have to be 6 words from a Diceware word list? Have you tried this? I haven’t tried (yet), but the benefit could be you only have one password (which obviously has to be very secure and preferably only in your mind) which protects all of the seeds you might have. And more importantly you can subsequently store all your seeds on plain paper in encrypted form just anywhere, also the master key doesn’t matter. Even post them on X :). But smart way to go is to combine the master key with a yubikey, that is possible. So you can use the yubikey for normal use and the master key as a backup. If you forget or lose the master key or password, you have the yubikey and the other way around. For a while I used Nitrokeys as the primary and the password as a backup, but providers changed to passkeys or phones instead 😖 and made that problematic. For really significant stuff, I sometimes used LUKS with key and password/pin. | |
Characters remaining: 10,000 comment guidelines | |
