# Should I be worried about backing up GPG keys?

**URL:** <https://community.passbolt.com/t/should-i-be-worried-about-backing-up-gpg-keys/5227>\
**Category:** Community Feedback\
**Created:** [April 10, 2022, 3:42pm UTC](https://community.passbolt.com/t/should-i-be-worried-about-backing-up-gpg-keys/5227 "2022-04-10T15:42:45Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![passbolt\_user](https://avatars.discourse-cdn.com/v4/letter/p/47e85d/32.png) [@passbolt\_user](https://community.passbolt.com/u/passbolt_user)\
**Post date:** [April 10, 2022, 3:42pm UTC](https://community.passbolt.com/t/should-i-be-worried-about-backing-up-gpg-keys/5227/1 "2022-04-10T15:42:45Z")

</div>

Hello,

I’m following the [guide](https://help.passbolt.com/hosting/backup/package.html) to set up automated backups for my passbolt installation. It says I also have to backup the public and private GPG keys used for authentication by the passbolt api.

However I’m concerned this might introduce a security issue? Like what if the backup itself is compromised, and someone gets access to the keys, couldn’t these be used misused? Should I be worrying about this?

---

<div class="post-metadata">

**Author:** ![garrett](https://yyz1.discourse-cdn.com/flex031/user_avatar/community.passbolt.com/garrett/32/545_2.png) [@garrett](https://community.passbolt.com/u/garrett)\
**Post date:** [April 10, 2022, 8:00pm UTC](https://community.passbolt.com/t/should-i-be-worried-about-backing-up-gpg-keys/5227/2 "2022-04-10T20:00:11Z")

</div>

Hi @passbolt_user Welcome to the forum! Definitely read the whitepaper if you haven’t already [https://help.passbolt.com/assets/files/Security%20White%20Paper%20-%20Passbolt%20Pro%20Edition.pdf](https://help.passbolt.com/assets/files/Security%20White%20Paper%20-%20Passbolt%20Pro%20Edition.pdf)

Risk mitigation strategies are discussed.

---

<div class="post-metadata">

**Author:** ![max](https://yyz1.discourse-cdn.com/flex031/user_avatar/community.passbolt.com/max/32/1528_2.png) [@max](https://community.passbolt.com/u/max)\
**Post date:** [April 11, 2022, 1:56pm UTC](https://community.passbolt.com/t/should-i-be-worried-about-backing-up-gpg-keys/5227/3 "2022-04-11T13:56:49Z")

</div>

Hi @passbolt_user,

The private key itself needs to be unlock with your passphrase. If the attacker got access to your private key, the entropy of your passphrase will be the last barrier to access your account.  
Take a look at this nice table made by a reddit user: [https://i.imgur.com/gfYw57t.png](https://i.imgur.com/gfYw57t.png)  
It’s fair to say that bruteforce attack on a passphrase are very unlikely to succeed if you got a decent entropy( and not leaked…) passphrase.

Best,  
Max

---

<div class="post-metadata">

**Author:** ![passbolt\_user](https://avatars.discourse-cdn.com/v4/letter/p/47e85d/32.png) [@passbolt\_user](https://community.passbolt.com/u/passbolt_user)\
**Post date:** [April 11, 2022, 10:32pm UTC](https://community.passbolt.com/t/should-i-be-worried-about-backing-up-gpg-keys/5227/4 "2022-04-11T22:32:17Z")

</div>

Hi, during the installation it says that I shouldn’t set any passphrase for the private key?

Maybe an attacker could use the private key and a compromised domain to spoof the passbolt server?

![image](https://canada1.discourse-cdn.com/flex031/uploads/passbolt/original/2X/d/d4c53a0ff409aade7b0167b2419fab2a02094063.png)

---

<div class="post-metadata">

**Author:** ![max](https://yyz1.discourse-cdn.com/flex031/user_avatar/community.passbolt.com/max/32/1528_2.png) [@max](https://community.passbolt.com/u/max)\
**Post date:** [April 11, 2022, 10:34pm UTC](https://community.passbolt.com/t/should-i-be-worried-about-backing-up-gpg-keys/5227/5 "2022-04-11T22:34:43Z")

</div>

Hi, for the private key of the server yes.

For the user’s private keys you need to.

Best,  
Max
