Show HN: Pgpkeygenerator.com – Generate OpenPGP keys online securely
pgpkeygenerator.comPGPkeygenerator.com is a free, online and secure PGP key generator. All code runs on the client-side. The OpenPGP.js library is used. A "secure" online key generator....when literally the sixth line of HTML in the page loads third-party analytics code (without even using SRI) into the page, which could then read the private key. Hard pass. Hello and thanks for your comment. I appreciate your feedback and have removed the third-party analytics code to enhance security and privacy. No online key generator is secure regardless if it's client side. You cannot make those types of security guarantees even if you go through audits or whatever. The web site's code could change at any time, or have third-party URLs, etc. Anyone trusting these types of services are being fooled into a false sense of security. Do NOT use this or any similar online service. Hello and thanks for your comment. 1. All online key generators should be approached with caution, however they can be a practical solution for users who may not be comfortable with offline key generation or lack technical expertise. 2. The code is run on the client-side. I do not have any third party code running - I have removed the Google Analytics code. This setup provides a reasonable level of security for many users. If you are that hardcore you can still use offline key generation but don't discourage users with blanket statements like 'do not use online services'. Key generation procedures for the Ordinary Joe usually begin with "make sure to disconnect your Ethernet cable and any other network connections..." so yeah, hard pass for me, too. Hello and thanks for your comment. You can unplug your Ethernet cable after you loaded the website and still generate a key. While offline key generation may offer an additional layer of security, online services can provide a more accessible and user-friendly option for individuals who prioritize convenience and still want a reasonable level of security.