drduh / YubiKey-Guide

Guide to using YubiKey for GnuPG and SSH
http://drduh.github.io/YubiKey-Guide/
MIT License
11.2k stars 1.19k forks source link

Paper backup instructions and pitfalls #3

Closed VFS closed 6 years ago

VFS commented 8 years ago

@drduh, would you mind including instructions on best practices to perform a secure backup of the master key on paper? Would be wise to also store a copy of the subkeys (S E A) stored on the yubikey? How hard would it be to password-protect them with a different password?

drduh commented 8 years ago

Is that a good idea? How would one read/enter a long private key back from paper? I'm not sure what advantage this would have over storing copies on encrypted, offline media. It ought to be possible to use different passphrases for each key, though it seems overkill.

wmarshdev commented 8 years ago

I think convenience is a non-issue for paper backups. It's just a case of having the master key on a medium that can't have a mechanical or electronic failure (not that paper is itself indestructible!).

http://www.jabberwocky.com/software/paperkey/ makes a good case.