The Resolvable Paranoia
I’m the relatively paranoid type and wanted to address some security blind spots. This post uses layman’s terms while citing technical sources, targeting intermediate developers seeking a comprehensive guide to secure machine setup.
SSH and GPG Keys
SSH Keys: Authentication mechanism using public-private key pairs. The public key resides on servers (can be shared openly), while the private key remains confidential. Used for passwordless server access and Git repository commits.
GPG Keys: More complex than SSH keys, used for signing messages/commits/software to verify authenticity and encrypting messages for intended recipients only.
Nine Logical Security Principles
- Keys shouldn’t transfer between devices - separate keys per device limit compromise scope
- Keys require passphrases - protects against hardware theft
- Replace keys annually - precautionary measure against undetected compromises
- Use different GPG keys for signing vs. encrypting - mathematical security reasons
- Never replace GPG signing keys - maintains long-term web of trust verification
- Store main GPG keys on air-gapped devices - maximum security isolation
- Delete keys with
shred, notrm- prevents recovery - Use FLOSS exclusively - enables code transparency and community review
- SSH: prefer ED25519 over RSA - shorter keys, same security, immune to side-channel attacks
Ground Rules Summary
- Unique key per system
- Passphrases mandatory
- Annual key rotation
- Permanent signing keys
- Separate encryption/signing GPG keys
- Air-gapped master GPG storage
- Secure deletion practices
- FLOSS preference
- Dual SSH key strategy
Storage and Backups
Apply 3-2-1 backup rule: maintain three copies across locations. Options include paper backups via paperkey, QR codes, USB sticks, or encrypted tomb containers. Avoid cloud storage.
SSH Key Creation
ED25519 Key:
ssh-keygen -a 100 -t ed25519 -f ~/.ssh/id_ed25519 -C "john.doe@mail.com"RSA Key:
ssh-keygen -a 100 -b 4096 -f ~/.ssh/id_rsa -C "john.doe@mail.com"Both require strong passphrases (10+ characters with mixed case, numbers, symbols).
GPG Key Creation
Use gpg2 --verbose --full-gen-key
Signing Key: Select option 4 (RSA sign only), 4096-bit, 0 expiration, include “Signing Key” in comment.
Encryption Key: Select option 1 (RSA and RSA), 4096-bit, 1-year expiration.
Strong passphrases are emphasized as critical protection against key theft.