7 ms·
Yubico with new 4096-bit keys and gpg-agent for ssh authentication
- wtbob 11y agoI'm surprised that more folks haven't just gone to 8,192-bit keys, out of an abundance of caution.
- mike-cardwell 11y ago4,096 is already an abundance of caution. You might as well say people should go to 32,768 just to be sure. Then somebody else would come along and say, "why not 65,536?"
- justinjlynn 11y agoIndeed. Mostly, it's just a question of whether or not the software will support a key of such size. Typically, I would recommend that, unless you've a good reason to use a smaller key (like support concerns), one should use the biggest key one possibly can use at the time the key is generated. Though, if one is doing key rotation as one should be, one can always adjust up as needed as time goes on.
- garrettr_ 11y agoNot really, especially in the context of RSA keys, because: 1. RSA is a slow algorithm and gets slower as you increase the key size. 2. Increasing the key size gets diminishing returns on the security margin. Given the performance and compatibility issues, the relatively minor improvement in security once you go beyond a certain key size is not worth it (you should switch to a better algorithm instead). 3. Anything over 4096 (possibly anything over 3072) is overkill anyway - if you could break a 4096-bit RSA key, you've probably found a fundamental weakness in RSA that means you should move to a different algorithm entirely.
- justinjlynn 11y agoall valid points.
- drdaeman 11y agoI think the general consensus was not extending RSA key size, but using elliptic curves instead? (But NIST and Brainpool curves aren't completely trustworthy and Curve25519 is not yet standardized for OpenPGP, so we're practically stuck with RSA at the moment)
- jlgaddis 11y agoAccording to Werner Koch: [0] "8192 bit keys are horrible insane from all POVs: There is no extra security because the security is based on the weakest link and this is definitely not the length of the RSA modulus, they make encryption really slow and thereby reducing the likeliness of widespread encryption use, they only help spreading FUD about the security of the RSA or other algorithms." [0]: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=137824#10 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=137824#10
- sofaofthedamned 11y agoAre the github keys they sold cheaply compatible with 4096 bit keys? I'm loathe to buy another, considering i've got 3 already...
- qrmn 11y agoAs far as I'm aware, Yubikey 4 and Yubikey Nano 4 can do 4096; the older ones like the NEO can only do 2048. Not that 2048 is flawed as such: it's still north of 100 bits workfactor at the moment, as far as I gather. 3072 would be equivalent to about 128 (similar to the EC algorithms secp256r1 or Curve25519), and 4096 is some extra insurance on top. (As a benchmark: Snowden used 4096-bit RSA keys for GnuPG.) Anything bigger than that could introduce OpenPGP compatibility troubles. All of these are secure when correctly implemented. (Yubikey use NXP chips. I don't have much to say beyond that, I haven't audited them.) All of them will fall to Shor's algorithm on a quantum computer of sufficient size, but we're not likely to have one of those for a good few years, if they're possible.
- pja 11y agoNo, because the github / U2F keys don’t have any writeable local storage.
- speedkills 11y agoI picked up two of the github keys. Never did get them working under OS X. Plug them in and nothing, not recognized by any of their tools, no new keyboard recognized prompt, nothing. Anyone else have trouble with them on OS X?
- arnarbi 11y agoDoes it light up when you try logging in or registering it with Github/Dropbox/Google in Chrome?
- gruturo 11y agoIs there any way to store an ssh server key in it, or an https server's key? Basically turning this into a mini-HSM ?
- deleted 11y ago[deleted]
- justinjlynn 11y agoYubico have a product specifically for that use case: https://www.yubico.com/products/yubihsm/ https://www.yubico.com/products/yubihsm/
- justinjlynn 11y agoMy mistake, it doesn't appear to support that functionality. I'll have to look into it further.
- gruturo 11y agoThere is also the non-insignificant issue of the $500 price tag. Wouldn't bat an eyelid if this was for professional/corporate use, but $500 out of my own pocket for my personal home server is a bit steep.
- mcpherrinm 11y agoAs best I can tell, the YubiHSM is basically only useful with their Yubico Validation Server for their proprietary 2FA solution.
- deleted 11y ago[deleted]
- EvanAnderson 11y agoYou might want to look at the Nitrokey HSM. I'm using one for a project and I was blown away by the feature set for the cost (as compared with the SafeNet devices I originally looked at). Its signing throughput is too slow to run a website with any significant new connection volume, but for personal applications it could be made to work. As just an HSM I think they're a phenomenal value.
- chx 11y agoMay I offer my article on an excellent password manager complementing the Yubico devices well? https://drupalwatchdog.com/blog/2015/6/yubikey-neo-and-better-password-manager-pass https://drupalwatchdog.com/blog/2015/6/yubikey-neo-and-bette...
- deno 11y agoNitrokey[1] is about the same price as Yubico but has open source firmware & hardware. You might also know them as CryptoStick[2]. [1] https://www.nitrokey.com/ https://www.nitrokey.com/ [2] https://blog.mozilla.org/security/2013/02/13/using-cryptostick-as-an-hsm/ https://blog.mozilla.org/security/2013/02/13/using-cryptosti...
- StavrosK 11y agoThat looks very nice, but it's rather more expensive than the Yubikey. The latter has NFC+U2F in a stick costing $50, whereas the former costs $50 for a stick that has neither.
- deno 11y agoWhat’s the use case for NFC?
- mike-cardwell 11y agoUsing PGP on your smartphone without giving it access to your PGP key - https://grepular.com/An_NFC_PGP_SmartCard_For_Android https://grepular.com/An_NFC_PGP_SmartCard_For_Android - That's how I use it anyway.
- justinjlynn 11y agoFor usage with mobile applications, where NFC is typically available but USB Host is not, I would imagine.
- JohnTHaller 11y agoOn Android, you typically have USB host (at least on any phone that someone interested in this tech would buy). On iOS it's moot since NFC is gimped and can't be used by apps.
- lorenzhs 11y ago
- beezle 11y agoLooked at these last year but opted for smartcard and secure pinpad reader instead.
- grhmc 11y agoCan you provide links to what you chose instead?
- mike-cardwell 11y agoI dunno about him, but I do something similar on one of my machines. I use an SCM SPR-532 USB reader with pinpad and an OpenPGP v2 smart card. More info and pictures here - https://grepular.com/Smart_Cards_and_SSH_Authentication https://grepular.com/Smart_Cards_and_SSH_Authentication
- gh02t 11y agoWhere did you get the PGP card? Did you donate to become a fellow? I've been thinking about it, but it's a bit confusing figuring out what cards are compatible and donating to the foundation is nice but a bit expensive.
- tokenizerrr 11y agoYou can get them here: http://shop.kernelconcepts.de/ http://shop.kernelconcepts.de/
- mike-cardwell 11y agoI got it from kernelconcepts as tokenizerrr said. They seem to have a newer version of the card now which does 4096, so I might have to buy another. Mine only does 2048
- late2part 11y agoIn the article it's written that the yubikey is tamper proof. This is not the case. They report their product as tamper evident but not tamper proof.
- grhmc 11y ago> Encrypting by default is a good idea. I suspect the author intended to say Signing by default is a good idea.
- tetraodonpuffer 11y agofor folks interested in more on yubikeys and gpg I also would suggest these two blog posts http://viccuad.me/blog/secure-yourself-part-1-airgapped-computer-and-GPG-smartcards/ http://viccuad.me/blog/secure-yourself-part-1-airgapped-comp... http://blog.josefsson.org/2014/06/23/offline-gnupg-master-key-and-subkeys-on-yubikey-neo-smartcard/ http://blog.josefsson.org/2014/06/23/offline-gnupg-master-ke...
- exabrial 11y agoDoes Yubico support ECDSA?
- spilk 11y agoI think it supports ECC keys in the PIV applet, but not in the OpenPGP applet.
- exabrial 11y agoOfftopic question: Is there any FDE software that supports keeping decryption keys on a network server? You would still need to enter user authentication to obtain the decryption key of course. Use case: We are a HIPAA environment, I want a hard drive to be useless if it is removed from the building.
- dbalan 11y agoBuy the one with smaller form factor. the device bends with very nominal pressure and if you are someone as me who works mostly on one device and need to move around a lot with it - unplugging and replugging the key is very cumbersome. You can leave the nano one in port and forget it until you need it in another device. My two cents from using a neo to store production ssh keys.
- spilk 11y agoJust so it's clear, the previous Yubikey NEO also supports gpg-agent for SSH authentication, not just the new Yubikey 4. I've been using one for months. It presents a standard smarcard CCID interface and runs an OpenPGP applet. The source to the actual Javacard applet that implements is available on Github: https://github.com/Yubico/ykneo-openpgp https://github.com/Yubico/ykneo-openpgp