difficulty of typing a complex gpg passphrase correctly on a smartphone = impossible.
I have decided to set the timeout before you have to type it again to 8 hours and type the passphrase with an external keyboard.
Our threat model is our onedrive account getting hacked or cloud provider snooping, this is what our system journal being gpg encrypted is meant to protect against.
we also use a yubikey to sign in to onedrive and have a passwordless account to make it more difficult to hack.
we don't really consider our phone getting stolen in that. the lock screen code, find my device/remote wipe and sd card encryption is meant to protect against this.













