diff options
| author | Daniel Micay <danielmicay@gmail.com> | 2020-03-17 21:42:46 -0400 |
|---|---|---|
| committer | Daniel Micay <danielmicay@gmail.com> | 2020-03-17 21:42:46 -0400 |
| commit | 316326ea1952eef35524afb0d3cedaf7c5ca342e (patch) | |
| tree | c29b6c871c5497886546eede76e19e2d912afbe0 /static/build.html | |
| parent | a641f31a2940c609e52251cd3c4e4cb4b774d6bf (diff) | |
clarification on encryption algorithm defaults
Diffstat (limited to 'static/build.html')
| -rw-r--r-- | static/build.html | 13 |
1 files changed, 7 insertions, 6 deletions
diff --git a/static/build.html b/static/build.html index 79ea1a50..4f218b30 100644 --- a/static/build.html +++ b/static/build.html @@ -431,12 +431,13 @@ mv vendor/android-prepare-vendor/DEVICE/BUILD_ID/vendor/google_devices/* vendor/ your own information.</p> <p>You should set a passphrase for the signing keys to keep them at rest until you - need to sign a release with them. By default, the keys are encrypted using scrypt for - key derivation and AES256 as the cipher. If you use swap, make sure it's encrypted, - ideally with an ephemeral key rather a persistent key to support hibernation. Even - with an ephemeral key, swap will reduce the security gained from encrypting the keys - since it breaks the guarantee that they become at rest as soon as the signing process - is finished. Consider disabling swap, at least during the signing process.</p> + need to sign a release with them. The GrapheneOS scripts (<code>make_key</code> and + <code>encrypt_keys.sh</code>) encrypt the signing keys using scrypt for key derivation + and AES256 as the cipher. If you use swap, make sure it's encrypted, ideally with an + ephemeral key rather a persistent key to support hibernation. Even with an ephemeral + key, swap will reduce the security gained from encrypting the keys since it breaks the + guarantee that they become at rest as soon as the signing process is finished. + Consider disabling swap, at least during the signing process.</p> <p>The encryption passphrase for all the keys generated for a device needs to match.</p> |
