Re: [Feature Request] multiple files sélection in addition to password and "no file" agent

Robert J. Hansen rjh at sixdemonbag.org
Thu Jun 11 14:25:44 CEST 2026


> so the one you used on every website, every ssh key, every gpg key, that 
> is created with the same pattern you usually use on all password that 
> leaked on the darknet? that i weak to dictonary attack? (just because 
> you're human, and human construct itself on patterns it employ)

What? No.

I memorize a 128-bit random sequence for my passphrase manager and use 
that to store everything else, and each year I print out the contents 
and drop a copy in my bank safe deposit box.

>> I'm glad you haven't had this experience. As soon as you do and 
>> discover your encrypted documents are now unreadable, you might change 
>> your mind.
 >
> it's 15 year or more that I use this...

When playing Russian roulette, the fact you haven't died yet should not 
fill you with confidence for the future.

>> You've invented a primitive key derivation function.
>>
>> Why is this better than Argon2 or PBKDF2, are modern, peer-reviewed, 
>> and successfully deployed key derivation functions?
 >
> i'm not, i'm just storing something in my brain that I can remember 
> easely

No, you've literally invented a primitive KDF.

Why use that primitive KDF over PBKDF2 or Argon2?

-------------- next part --------------
A non-text attachment was scrubbed...
Name: OpenPGP_signature.asc
Type: application/pgp-signature
Size: 236 bytes
Desc: OpenPGP digital signature
URL: <https://lists.gnupg.org/pipermail/gnupg-devel/attachments/20260611/8866319b/attachment.sig>


More information about the Gnupg-devel mailing list