Creating The Perfect GPG Keypair
alexcabal.com
alexcabal.com
I'd take an RSA 2048 smartcard before an RSA 4096 on my Mac.
http://shop.kernelconcepts.de/product_info.php?products_id=4...
A type 2 pinpad + openpgp smartcard might be the best practical thing right now -- a PIN on the card, plus a passphrase from the host (I think you can require both?). Type 3 showing a hash of what you sign, or a serial number of number of signs, would be even better.
The GPF cryptostick (usb) is also nice -- I think you could also take the Werner smartcard and cut it down to a smaller size for a USB stick sized reader. Sadly GPF stick 1.2 is out of stock everywhere.
I really wanted the CryptoStick, looks like they're temporarily about of stock pending the new 2.0 revision, but not holding my breath.
Yup, personally I've stuck my OpenPGP card in a Gemplus GemPC USB Shell Token v2:
http://www.cdw.com/shop/products/Gemplus-GemPC-USB-Shell-Tok...
If you get the OpenPGP card with a SIM cut-out, assembly is a breeze. Almost as good as a GPF stick.
http://www.yubico.com/products/yubikey-hardware/yubikey-neo/
It does a lot more than just a standard smart card though. Here's a good post on how it interacts with OpenPGP:
The solution is end user verifiable designs. Harder with hardware, but there have to be ways to do it. The risk is highest for single purpose vs general purpose devices. If safenet hsms aren't owned as fuck, I'll eat one.
However, even this guide is probably a little too long, and unfortunately many will not take the time to read it.
Oh yeah also the primary key is called, well, primary, not master. I do that mistake pretty often tho.
For example, I might want to have the ability to sigh messages on an ipad, and revoke the keyif the device is stolen.
Surely, surely it would be easier to just make two keypairs, store the master and then sign your "daily driver" key? This seems like a lot of effort making gpg do things it doesn't want to do for little practical gain - the full perfect key is still ideally offline.
We all use osx though so if any of us become high-value targets they'll just root our machines remotely with the help of Apple software update and steal our keys from ram or log our keystrokes directly.
I like the concept of passphrases, but they're too long to be manageable when you need to type them in a bunch of times.
(Passphrase was around the sime size as your first paragraph and was used for login, ssh, svn, git, email 82 and internal websites like bug trackers and wikis).
There is also no way to verify that the OSX keychain does not perform key escrow, as it is closed source.