3 ms·
Store your keys on a hardware token to reduce the chances of this happening (Nitrokey, Yubikey, OpenPGP smart card, etc.)
by spilk 10y ago
Store your keys on a hardware token to reduce the chances of this happening (Nitrokey, Yubikey, OpenPGP smart card, etc.)
- jason_slack 10y agothe way I read about Yubikey is that it is for websites, accounts, etc. Can you use it to log into your actual OS?
- toyg 10y agoYes, with a bit of setup and depending on your OS. My problem with hardware tokens is simply that I lose them.
- gargravarr 10y agoI keep mine on my car keys. Problem solved.
- jaeh 10y agoThen you (inevitably, Murphy's ...) lose your car keys. Now you have two problems. :p
- superobserver 10y agoOr stow a backup of your (yubikey) hardware in an encrypted (hopefully, zero-knowledge based) cloud service and restore when lost.
- gargravarr 10y agoYou can. The Yubikey can store a hash value in its second slot to act as a hardware token. I used to use mine with PAM so I couldn't get into my user account without it: https://developers.yubico.com/yubico-pam/ https://developers.yubico.com/yubico-pam/
- spilk 10y agoThe Yubikey NEO (and the 4, but the 4 is more closed-source than the NEO) is basically a Javacard smartcard with OpenPGP and PIV (x.509) applets with standard interfaces. I have my GPG auth/sign/encrypt subkeys on it (master/certification key stays offline), and with gpg-agent it will present your GPG auth key as SSH credentials. There are Yubikey-specific PAM modules you can use as a second factor for logging in locally, and there are probably ways to use standard smartcard authentication for login purposes as well but I don't have experience with that. I mainly use it for remote SSH login purposes.
- eeZi 10y agoThey'd backdoor your machine instead. Same result.
- spilk 10y agoSame result? With something like a Yubikey you can't (excepting any vulnerabilities) extract the private key data even with the admin PIN codes. Based on your PIN caching preferences an attacker may be able to sign/encrypt/decrypt data with your keys (suggest setting force PIN for sign and low TTL for pin caching in gpg-agent) but they won't be able to exfiltrate your private keys.