News Feed
  • DrugHub has agreed to fully refund all users who lost money in the SuperMarket exit scam.  
  • Retro Market has gone offline. Circumstances of the closure unknown.  
  • SuperMarket has closed following an exit scam by one of the admins.  
  • The admin of Incognito Market, Pharoah, has been arrested by the FBI several months after exit scamming.  
  • Silk RoadTorhoo mini logo
  • darknet markets list
  • Popular P2P exchange LocalMonero has announced it is closing.  

When should I have my key expire? : PGP | Torhoo darknet markets

When should I set my key to expire? I currently have it at around 1 year (2027), but im wondering if I should go for 2 or even 3.
What do you think?
/u/meatt 🍼
2 points
4 days ago
never
/u/Beelzebub
1 points
4 days ago
This guy is right. It's a headache to have to change it everywhere when it expires.
/u/pgpfreak P Moderator
2 points
4 days ago*
This is a good question. I had trouble deciding what to write in the tutorials about it.
First, you have to acknowledge the expiration date is mostly an informative value. An expired key is still working perfectly: you can sign, encrypt, decrypt. However, most PGP compatible application will consider this information for security purposes. Kleopatra will display a big red flag about the key being expired, most markets will ask you to provide a new one, etc. But that's on the receiver to decide how to react. Therefore the choice of an expiration date is mostly a safety measure you impose to yourself. In the event your key would be lost or compromised, it will mitigate the damage done by an attacker overtime, as it will eventually expire.
As /u/meatt suggested, you can perfectly give up on this by not setting one. It will definitively make your life easier. I'd argue it is the best choice for a personal quantity buyer or for a non-sensitive key, such as the one you use for Dread 2FA. However, I like to see an expiration date on vendor's key. It basically makes up for a canary, as the vendor has to prove they have ownership of the signing subkey once in a while. But this creates additional difficulties for the buyer as they have to update the public key each time the previous expire to ensure it's still active.