Preston Maness ☭<p><span class="h-card" translate="no"><a href="https://discuss.systems/@ahelwer" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>ahelwer</span></a></span> I've been using smartcards for about a decade now. Works well enough for keeping three 4096-bit RSA subkeys around on a more-secure-than-not environment. But rather than have the card generate the private keys, I generated the private keys on an airgapped machine, and keep encrypted copies elsewhere (USB drives) for when I needed to change smart cards, which has happened once so far.</p><p><a href="https://tenforward.social/tags/gpg" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>gpg</span></a> <a href="https://tenforward.social/tags/SmartCard" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SmartCard</span></a> <a href="https://tenforward.social/tags/GnuPG" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GnuPG</span></a> <a href="https://tenforward.social/tags/pgp" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>pgp</span></a></p>