Skip to main content


GPG Key Managing


Hey guys, I wanted to ask you how you manage your gpg keys? Having them in plaintext all the time on my hard drive feels unsecure.

I have my ssh keys in a password manager (KeePassXC) that only exposes them to the keyagend, when unlocked. Do you know if something like that exists for pgp too?

in reply to Zenlix

A hardware solution is the best route, Yubikey and/or smartcard.

Linux reshared this.

in reply to Zenlix

You should not store your privates keys unencrypted. In fact by default your keys are stored password protected just as if you'd store them in keepass.
in reply to Zenlix

I store them in an app on my phone behind password protection
in reply to Zenlix

Is also storing your gpg keys in KPXC unsuitable for your purposes?
in reply to SMillerNL

This is very interesting information!

I'd like to note that it's likely that several recommendations used as examples have been superseded with information around privacyguides.org/en/real-time… and similar locations, since expressing "use WhatsApp" makes me suspicious (and "use Wire" does not make me more confident): makeuseof.com/why-i-dont-trust… proton.me/blog/is-whatsapp-saf…

in reply to Zenlix

This entry was edited (7 hours ago)