Security Basics mailing list archives

Re: Crypto Question


From: John Borwick <borwicjh () wfu edu>
Date: Fri, 07 Nov 2003 14:13:37 -0500

McGill, Lachlan wrote:

Am I right in assuming that an encrypted file/email is only as secure as the
> passphrase used for the private key? i.e. If i use the passphrase
'password'  then does it become irrelevant what key size I use to encrypt the
> data?

You have two distinct levels of security:
  * the private key itself
  * the passphrase used to "unlock" the private key

Your passphrase only comes into play once someone has your private key. If someone gets your private key, your last line of defense is that password.

--
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
John Borwick                                     work      336 758 2507
Systems Infrastructure                           cell      336 391 6623
Wake Forest University                           email borwicjh () wfu edu

Attachment: _bin
Description:


Current thread: