Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I forgot my PGP passphrase and can no longer sign Java packages in the Sonatype maven repository. This is not a big deal for me but I did try to recover my passphrase.

I got an extension to John the Ripper that supports Gnu PGP keys and built a dictionary of permutations of words that I think I could have used in the passphrase.

I got nowhere. In this case, a passphrase > 20 characters was unbreakable to someone with modest computing power and an appropriate dictionary.

Edit: I did not save a revoke certificate because the Sonatype instructions did not include this step.



How far you get as a private effort is not really characterizing the threat; the threat is a determined attacker with AMD GPUs by the dozen. And while it is easy to discount state-sized efforts as being uninterested in signing your Java packages, the real threat are the hobbyists and criminally minded pros who really do have rigs and really do brag about how they do go attack the long lists of hashed passwords that often turn up after website breaches.

Please use bcrypt on your new key, the one you will be writing down the password to ;)


Even those who don't have such rigs can just rent them from, for example, Moxie Marlinspike's Cloud Cracker: https://www.cloudcracker.com/




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: