Pet usability peeve triggered here. If we create a system that completely depends on the strength of a password/passphrase we have to give the user concrete advice on how to create a password/passphrase that will be strong on that particular system.
Pet usability peeve triggered here. If we create a system that completely depends on the strength of a password/passphrase we have to give the user concrete advice on how to create a password/passphrase that will be strong on that particular system.
However, generally speaking, age uses scrypt for password key derivation, with a default work factor of 2^18 (1 second on modern machines). Unlike GnuPG's S2K, scrypt is both CPU and memory hard.
This gets back to my original peeve. This sort of thing has to be worked out for the user. I looked through the available documentation. Was I as a user expected to look through the source code and figure it out for myself?
I managed to get two things wrong in one post. As a result I ended up disparaging the Age project for no reason and causing confusion about the Pa project. I continued the confusion in subsequent replies.
I will try to be better about this sort of thing in the future and am sorry.
So I really should of complained that this fact was not made very clear to the user... :)
how could i have made this more clear? what would you like to see?
Did you even bother to check?
https://github.com/FiloSottile/age/blob/main/scrypt.go
This isn't exactly hidden.
If anyone else (i.e. "a user") made this mistake, I'd be more sympathetic. But not for you.
You don't get to have your cake and eat it too. Are you a cryptography expert, or aren't you?
If yes, then failing to bother to check the source code is a faux pas.
If no, then I expect you to stop trying to argue as a cryptography expert the next time someone points out that PGP is bad cryptography.
I don't care which you choose. I only ask that you stick to it.