[Duplicity-talk] Encryption password selection

From: Yves Goergen
Subject: [Duplicity-talk] Encryption password selection
Date: Mon, 08 Dec 2014 18:08:03 +0100
For duplicity 0.6.23 (Ubuntu 14.04), what are the recommendations for selecting an encryption password? I can't find any information about how it's even used and what requirements (minimum/maximum length, allowed characters) there are.

Also, I've never seen a system encrypting and signing data with a password only (no key file involved), and now I've read that duplicity also signs the backup volumes and can detect changes to it. Is that true or have I misunderstood something? I only know GnuPG with keys, not with passwords only.

