Thank you. Is asking the user to set and remember an encryption string the correct way? The only downside I can think of is that he may forget it, which is irrecoverable.
> Is asking the user to set and remember an encryption string the correct way?
That wouldn't be remotely sufficient for two reasons:
1) The user-supplied string will not to be random.
2) You need a constant series of random values that is as long as the data you're wanting to encrypt. If the user is securing a 2k long ASCII text, then you need 2k new random numbers for it.