My GPG key expires in December, because I accepted the default 1 year expiration that GPG offers. I now regularly use GPG to sign my email, and I’ve just renewed my pobox.com account ($15/yr for email and website forwarding), so I’m going to want another key.

Maybe I’ll let this one last for longer, or I’ll do the “right thing” and print out a ASCII-armored key invalidation that I can type into the computer if my key is ever compromised. But what if I lose the key? And I lose the paper? I think I’ve already let one key float around, never to be invalidated, and I’d tend to want a 5-year key or something over an infinite-year key.