36 ms·
Show HN: Kryptonite – a new home for your SSH private key
- 4kevinking 9y agoHey HN! We've built a way to generate an SSH key on your phone and use it from your computer such that the private key never leaves the phone. We were inspired by the threat model of USB HSMs like the Yubikey and set out to build a free, public source, and easier to use BYOD alternative. Looking forward to your questions!
- falcolas 9y agoThe Yubikey (as in generate and store SSH keys on the Yubikey) is not exactly a hard to use option. It's not as nicely packaged, but quite functional. EDIT: I'd love to talk about this, if someone has a differing opinion. Once set up, it was dirt simple to use.
- StavrosK 9y agoI am of the same opinion. I added the library in my SSH config and now SSH will just use the yubikey, if it's plugged in. The only problem is that I haven't been able to find an agent supporting all of (gnome keyring for persistent passwords, ed25519 keys, the yubikey).
- newman314 9y agoSome questions & comments: * Can you have multiple private keys (site specific?)? * Does the Android client support ed25519 keys or is it iOS only? * Please modify your curl statement to be something like how Honeycomb does it (that is include a checksum test). https://honeycomb.io/docs/connect/nginx/ https://honeycomb.io/docs/connect/nginx/
- 4kevinking 9y ago1) We are planning to support multiple private keys, but currently only support a single key pair. 2) Android doesn't yet support ed25519 but it is coming. 3) We would consider something like this but the question is how that checksum test itself is served. We'll definitely look into improving this. The curl script itself does check the hashes of the installed binaries downloaded from github.
- tptacek 9y agoMultiple private keys are more important than you might think, because Github won't let you use the same key in more than one account, so everyone who has more than one Github account and wants hardware tokens has to have multiple hardware tokens.
- 4kevinking 9y agoI didn't realize that, thanks for letting us know! We're actively working on this
- dolmen 9y agoAs you seem to use multiple GitHub accounts with SSH, you might be interested by the ssh_config tricks that I implemented in github-keygen https://github.com/dolmen/github-keygen/ https://github.com/dolmen/github-keygen/
- pquerna 9y agoI love the transparency of having your source on Github, but the license ambiguity isn't ideal when revealing this to the world: We are currently working on a new license for Kryptonite. For now, the code is released under All Rights Reserved. https://github.com/KryptCo/kr#license https://github.com/KryptCo/kr#license Soon as I see that, I've got to close the tab, so does anyone who cares about IP. (disclaimer: i'm a co-founder of ScaleFT)
- dudus 9y agoIs proprietary code even allowed on GitHub?
- shimon_e 9y agoYes
- stordoff 9y agoYou grant some rights to other users of GitHub, but I'm not seeing anything that prevents proprietary code: > If you set your pages and repositories to be viewed publicly, you grant each User of GitHub a nonexclusive, worldwide license to access your Content through the GitHub Service, and to use, display and perform your Content, and to reproduce your Content solely on GitHub as permitted through GitHub's functionality. You may grant further rights if you adopt a license. https://help.github.com/articles/github-terms-of-service/ https://help.github.com/articles/github-terms-of-service/ To anyone more versed in US law than me, what usage specifically does "use, display and perform your Content" permit?
- Ajedi32 9y agoHow's that ambiguous? The code is proprietary; all rights reserved. Seems like they're planning to change that in the future, but in the meantime the existing license seems pretty clear to me.
- jaytaylor 9y agoFor one of the main repos: https://github.com/KryptCo/kr https://github.com/KryptCo/kr 57% Go 40% Rust First time I've seen them paired together in the wild like this, very cool!
- 4kevinking 9y agoThanks! We love Go for its SSH support and Rust for its dylib / crypto libraries.
- BlackLotus89 9y agohttps://news.ycombinator.com/item?id=14121780 https://news.ycombinator.com/item?id=14121780 on go ssh security And what is the use of this when it runs on a platform that is an active target for every intelligence agency in the world with irregular updates, regular security problems and other problems like preinstalled spyware and so on? Nice idea, but only if the phone was a platform you could trust.
- sp0ck 9y agoThose two languages are lowering attack surface by huge factor ! :) What a amazing combination.
- rileytg 9y agolicense :( this exact thing is on my devs teams backlog. if you figure out a good license it would be AMAZING for us.
- j_s 9y agoGPLv3 should be enough for an app; AGPL adds additional protection for server-side/self-hosted projects. https://softwareengineering.stackexchange.com/questions/142012/using-an-agpl-3-0-licensed-library-for-extra-functionality-in-an-ios-app https://softwareengineering.stackexchange.com/questions/1420... The MuPDF app is available under AGPLv3+. https://itunes.apple.com/us/app/mupdf/id482941798?mt=8 https://itunes.apple.com/us/app/mupdf/id482941798?mt=8 You will catch some flak for discouraging free commercial re-use. If you see your app or portions of it as more of a library for others to use then LGPL is an option that requires reciprocity. In an unusual case, a "lax" license was recommended for the reference Ogg/Vorbis audio codec implementation: https://lwn.net/2001/0301/a/rms-ov-license.php3 https://lwn.net/2001/0301/a/rms-ov-license.php3
- stephenr 9y ago> AGPL adds additional restrictions for server-side/self-hosted projects Fixed that for you.
- laken 9y agoAny chance of a UWP/Windows Phone app in the future?
- cynix 9y agoCan't seem to create both an RSA and an Ed25519 key.
- 4kevinking 9y agoCorrect, we currently only support one key, but multiple key support is in the works!
- cynix 9y agoAny plans to support FreeBSD?
- bartvk 9y agoThat looks pretty cool. You do have to make sure to back up your phone.
- eof 9y agoWhy do I want my private key on my phone instead of the computer where I am using it?
- falcolas 9y agoEven if your computer is 100% compromised, SSH can't be used without your explicit permission and knowledge.
- daveloyall 9y agoI think you're saying that if you use this app, and remove other ssh keys from your computer, then "SSH can't be used without your explicit permission and knowledge.". I agree with another commentator, I trust my PC more than I trust my phone. The latter is probably already compromised.
- noja 9y agoI'd like to know this too. My computer is patched daily, my phone less often.
- tptacek 9y agoRespectfully, this is easy: get a better phone and turn autoupdate on.
- h4waii 9y agoAlso respectfully, he stated patched daily. Generally, security updates for both iOS and Android devices happen in a monthly roll-up. If your checklist for being "secure" involves being up-to-date, there is no amount of 'getting a better phone' that will put it on par with a desktop OS that receives daily patches.
- tptacek 9y agoThis is simply not true. No matter how often you patch your Linux desktop, it is less secure than an iPhone.
- akerl_ 9y agoAre the communications between the phone and the computer going via the kryptonite servers?
- 4kevinking 9y agoNo -- we treat every communication channel as untrusted. All communication between the phone and computer is encrypted with session keys established when you pair by scanning the QR code in the terminal. Check out our architecture post for more details: https://blog.krypt.co/the-kryptonite-architecture-a385e7aaa336 https://blog.krypt.co/the-kryptonite-architecture-a385e7aaa3...
- akerl_ 9y agoIf I'm reading this, the answer is actually ~Yes? The requests pass via SQS/SNS run by Kryptonite, or via Bluetooth not run by kryptonite?
- 4kevinking 9y agoIndeed, (encrypted) requests pass through SQS/SNS with credentials owned by us. We can see the amount of traffic, but not any of its contents or who sent it.
- henryfjordan 9y agoFollow-up: Since it seems all the code is open-source, is it possible for me to run this service on my own server (or at least in my own AWS setup)?
- bobwaycott 9y agoThe lack of a license leaves this very unclear.
- elahd 9y ago
- falcolas 9y agoSeems quite similar to using a Yubikey to house your SSH key, just with bluetooth and your phone. A bit less secure, but still quite the interesting tool.
- Artemis2 9y agoHi, that looks good! I'll probably try it out soon. One suggestion regarding PCI DSS: you should probably make a page/whitepaper that outlines the compliance story of Kryptonite. ScaleFT has a great one: https://www.scaleft.com/use-cases/pci-dss/ https://www.scaleft.com/use-cases/pci-dss/. By the way, have you checked that you do not need to be compliant yourself?
- ShakataGaNai 9y agoTheoretically this solution could be classified as a mutlti-factor authentication, which covers PCI DSS Requirement 8.2. See also https://www.pcisecuritystandards.org/pdfs/Multi-Factor-Authentication-Guidance-v1.pdf https://www.pcisecuritystandards.org/pdfs/Multi-Factor-Authe... Beyond that, there isn't much else this does regarding PCI. SSH does the rest.
- bizzleDawg 9y agoObvious question - What happens when the phone containing the private key is lost?
- daveloyall 9y agohttps://krypt.co/faq/ https://krypt.co/faq/
- vorotato 9y agoFirst make sure you remove the old SSH public key from any of your accounts. Once you have Kryptonite installed on your new phone, add the new public key to the accounts you were using SSH with before.
- elahd 9y agoSounds like you ultimately need a backup method for logging into your server -- probably a second, non-Kryptonite key (or another admin user). Is that correct?
- 4kevinking 9y agoThat is correct. We will also soon release a way to copy a key from one device to another by scanning a QR code.
- daveloyall 9y agoDoes this allow me to ssh into my server, for example, a shell server on the internet? If so, how does the server contact my phone? Through your server, right? What software do I install on the server for that?
- 4kevinking 9y agoKryptonite allows you to use SSH on your computer, but authenticate with a private key protected on your phone. It doesn't require any changes to the server, just the Kryptonite app and our workstation software.
- daveloyall 9y agoI found the answer on your blog: > Our system consists of three components: > (1) the Kryptonite phone app for iOS and Android, > (2) the krd daemon that runs in the background on a macOS or Linux computer, and > (3) the kr command line utility that manages krd. ...from https://blog.krypt.co/the-kryptonite-architecture-a385e7aaa336 https://blog.krypt.co/the-kryptonite-architecture-a385e7aaa3... Sounds like `krd` is why I likely won't be using this. Try implementing it as a PAM module or something. [edit: formatting]
- daveloyall 9y agoOk, `krd` is an alternative `ssh-agent`, I see. So my suggestion re: PAM is irrelevant because you aren't changing the server, you're changing the client. Ok, I'm interested ...maybe... I'll wait until people more familiar with ssh-agent chime in. :)
- finnn 9y agoAn SSH agent is the correct way to provide access to private SSH keys, just like OpenSSH's ssh-agent does. I could be wrong but I'm not aware of any way to implement this as a PAM module, unless it was something that was installed on all the servers you SSH'd into, which would be super annoying to setup.
- deleted 9y ago[deleted]
- trizic 9y agoYour FAQ says you cannot backup your private key. So does that mean if your service gets attacked by DDoS or has unexpected downtime, you will not be able to SSH into your server?
- agrinman 9y agoKryptonite works over bluetooth too, so even if AWS SQS is down, you'll still be able to use your private key
- deleted 9y ago[deleted]
- jamiesonbecker 9y agoCan this work with Userify to distribute the public key?
- 4kevinking 9y agoYep! Just type 'kr me' to print your public key, or 'kr copy' to copy it right to your clipboard.
- deleted 9y ago[deleted]
- shmel 9y agoIt sounds very hipster and all, but how is a phone more trustworthy than a Linux PC? Cool, we don't need to trust a PC, now we have to trust a phone and pretend that malware for smartphones don't exist at all. Hardware USB token looks much better as its attack surface is so much smaller than iOS/Android.
- 4kevinking 9y agoThe attack surface may seem smaller for USB tokens, but storing the pin for say a Yubikey allows malware to use the key without restriction. Also, these USB devices don't have a UI, so you never know what you are actually approving, i.e. which username or server you are logging into.
- packetized 9y agoErm, not true - changing the Yubikey setting to require a touch for key use (S/C/E) is trivial. Malware can't use it without restriction if it requires you to physically touch it every time you want to approve use.
- 4kevinking 9y agoPoint taken. Unfortunately when you touch the key you still can't verify exactly what you are approving.
- simonvc 9y agoThere's a GPG/SSH applet for the ledger Nano S now that has a tiny screen and buttons...
- wwwv 9y agoSo, capture the auth and use it for the malware, show the user some failure and allow their retry to pass. Stupid dodgy Yubikey fails half the time.
- tptacek 9y ago
- sweis 9y agoWhy are you doing this instead of SHA[N]withRSA? https://github.com/KryptCo/kryptonite-android/blob/master/app/src/main/java/co/krypt/kryptonite/crypto/SSHKeyPair.java#L60 https://github.com/KryptCo/kryptonite-android/blob/master/ap...
- 4kevinking 9y agoWe do the hashing ourselves so that it's easy to use any hash function in the future. If you create a Keystore key but decide to use a hash function you didn't specify at generation time, it will be rejected by the API.
- sweis 9y agoI don't know if you've done it correctly. You can use the built-in signature digest support and still add support for whatever you want in the future.
- y7 9y agoClever that it uses the client instead of the server! I've dabbled with phone-based authentication via a server-side PAM module before, but you generally don't have full control over the servers you SSH into. Although the question remains: is this more secure than just storing your key on your computer? If you're assuming your machine to be compromised, then as soon as you login to another server you've basically given your attacker potential access there as well.
- sdca 9y agoYou've hit the nail on the head. If your computer's ssh binary can be compromised so can krd. If the main objective is to prevent other apps in user space from reading unlocked private keys, why not just ssh/sudo into a secondary account where the default shell is set to an ssh client?
- yzmtf2008 9y agoThe point is, even when krd is compromised, the malicious party cannot gain access to your private key. They key is only stored on your phone and you have to physically confirm the login from your phone.
- xorfish 9y agoIs the private key still worth something if the attacker has access to the server?
- tptacek 9y agoI haven't reviewed the implementation, but this is a really good idea. I want one.
- patio11 9y agoI will likely end up using this in personal capacity, and would also appreciate if the UX of using Google Authenticator were more similar to this, rather than requiring me to screenscrape my phone with my eyeball and then type information into another device (or, more painfully, another window on the same phone). The easiest way to do that probably results in a callback to Big Daddy G every time I access anything sensitive and I'm cool with that.
- plange 9y ago> The easiest way to do that probably results in a callback to Big Daddy G every time I access anything sensitive and I'm cool with that. Why?!
- kasey_junk 9y agoBecause they have one of the most competent security teams in the world and enough money to mount legal defenses against governmental adversaries. For many many threat models this pairing is a more competent defense than just about any thing a single person could come up with.
- pvg 9y agoThe Google App can do this on iOS, rather than Google Authenticator, for some reason. https://support.google.com/accounts/answer/6361026?hl=en https://support.google.com/accounts/answer/6361026?hl=en
- jitl 9y agoWith Apple's devices, you can copy-paste your 2nd factor token between devices, which makes things much more convenient. Although cloud copy-paste is still significantly slower than tapping "Allow" in a notification, it's lower friction than manually typing those numbers. Although the security of cloud copy-paste I haven't investigated...
- xg15 9y agoThe faq says there is intentionally no way to extract the private key due to security. But this means I need a second account in case my phone gets lost - the key of which I once again need to secure. How is that more secure than letting me backup the private key in the first place?
- detaro 9y agoNot everything needs a key backup. If you create a backup key, you can create it on another device (ideally the one it's going to be used from) and don't have to move it off the phone in a way where it could be exposed (As much as one would think people using stuff like this should know better, I wouldn't be surprised if at least some got the backup off their phone by e-mailing it to themselves or something along those lines)
- 4kevinking 9y agoThe current version is designed for hosted services like GitHub, redeployable infrastructure, and servers to which multiple people have access. We totally understand your use case and are actively working on implementing transferring a key to another device or printing out a paper backup.
- xg15 9y agoThat makes sense. Looking forward to the development of your product then!
- deleted 9y ago[deleted]
- wwwv 9y agoHow does this handle SSH session re-keying, does that need further authentication from the device? openssh does this pretty infrequently, I can't immediately remember if that needs participation with the asymmetric key or not. ED: Seems it's just as if you re-did the cipher negotiation, so no asymmetric interaction.
- cyberferret 9y agoSeems pretty cool - I've just installed it and having a play with it. A couple of questions: 1. So I have to update all my servers to use my Kryptonite SSH key from the current Private Keys that I have? 2. This solution still doesn't allow me to SSH into my servers from another machine that doesn't have my private keys on it (such as a colleague's Mac), does it?
- agrinman 9y ago1. You have to upload your Kryptonite public key to ~/.ssh/authorized_keys on all the servers you want to access with your Kryptonite key. Take a look at the unlisted command `kr add`to help with this. It automatically adds your kryptonite public key to a server you specify: i.e. `kr add user@server` add your Kryptonite public key to the authorized_keys file for account `user` on `server`. 2. It does actually. All you need to do is pair with your colleague's mac. Run `kr pair` on their machine, Kryptonite can be paired with unlimited computers such as your work and home computers. You'll be able to ssh to all your servers using the Kryptonite key.
- cyberferret 9y agoAh! Great - thank you. Overall, I am amazed at the simplicity of managing keys using this platform.
- ams6110 9y agoWell as of now it apparently manages one key.
- exabrial 9y agoI don't have root access on my phone, and Samsung only releases patches if their phones catch on fire. No thanks. Good idea though, but flawed execution.
- throwaway2048 9y agoNo, instead you wanna deliver driveby opinions without defending them.
- dang 9y agoPlease be civil. We detached this comment from https://news.ycombinator.com/item?id=14241907 https://news.ycombinator.com/item?id=14241907 and marked it off-topic.
- netsec_burn 9y agoSo the new way to secure your private keys is in a location you DON'T control and validation by text message? It's May 1st not April 1st.
- 4kevinking 9y agoI think you may have misunderstood our architecture. SMS doesn't play any role in Kryptonite and all communication between the phone and computer is encrypted and authenticated. Check out a full explanation of the architecture here: https://blog.krypt.co/the-kryptonite-architecture-a385e7aaa336 https://blog.krypt.co/the-kryptonite-architecture-a385e7aaa3...
- snowpalmer 9y agoLooks interesting. However, it seems to maybe assume you're using bash? Using the fish-shell it seems to have simply broken ssh and git operations with incorrect syntax. I had to run `kr uninstall` to get things back to normal (it fails when it's running fish or if I drop into bash so it's somehow looking at my default shell.) I submitted a ticket on the repo.
- 4kevinking 9y agoThanks, will fix this asap. We have tested on bash, zsh, and fish on macOS but it seems we missed an edge case. I'll follow up with your ticket.
- nyolfen 9y agocame here to make note of this as well. thanks for the prompt fix, i'll check it out again in a couple of days :)
- 4kevinking 9y agofish shell should be working now, let us know if you have any other issues!
- rdavis 9y agoIt's working great in my fish shell now. Thanks for the speedy update!
- 4kevinking 9y agogreat to hear, thanks!
- nyolfen 9y agoworks perfect -- this is really slick!
- feld 9y agoThey certainly seem to have a marketable product for easy ssh key management. They'll make buckets of money on this I bet.
- dffds 9y agoVery cool!
- dffds 9y agoVery cool!
- shusson 9y agoI love the concept, but I think the added complexity is hard to trust, at least for now.
- lucb1e 9y agoIn terms of possible compromise, I rate the possibility that my phone is compromised way higher than my laptop. Adding a factor is a good idea in terms of security (not in terms of availability and ease of use, but definitely in security), but replacing it entirely... No. Why'd I even want to remove id_rsa? What's the problem being solved here?
- agrinman 9y agoThe problem is that your private key stored in ~/.ssh/id_rsa can be read by any user-level application. The private key is even vulnerable if you passphrase encrypt it. See our deep dive into the threat model: https://blog.krypt.co/why-store-an-ssh-key-with-kryptonite-9f24c1f983d5 https://blog.krypt.co/why-store-an-ssh-key-with-kryptonite-9... This is why we move it off the computer and onto a phone. The security is comparable to using a Yubikey. I'm not sure why you say your phone is less secure than your laptop. On the phone, apps are sandboxed and the private key never leaves the Kryptonite sandbox.
- jobbee 9y agoI also share the opinion that the threat model is flawed, biased. You define it "deep dive" but you didn't even scratch the surface of the issue. > At the core, phone operating systems are built with better sandboxing than their desktop counterparts. This is why security experts like Matt Green recommend phones for your most sensitive data. Having a better sandboxing is not the same as having a "safe sandboxing". How secure is the application once an attacker is able to compromise the sandboxing? IMHO the rest of the threat model "deep dive" has no value once we take that attack scenario into account. What about a non-dictionary based 20chars password protecting your private key, or storing your SSH key on an OpenPGP Smartcard in a USB token, a Yubikey or a Nitrokey (www.nitrokey.com)? I believe that it would be much more secure than application whose security model is based on the sole sandboxing.
- claudius 9y agoNeither Google nor Apple have root access on a Yubikey, nor does that key have some sort of wireless transmitter included which would allow for unnoticed data transfer to or from the key. Furthermore, it is nowadays largely trivial to set up sandboxing within a single user (using SELinux, Apparmor or whatever else) or to use multiple users and classical privilege separation to achieve the same effect. It is also telling that your "Threat Models" in the link above do not discuss attacks against the phone at all. Edit to add: You currently also do not have the ability to use my keys. If I were to install the app (and set it to auto-update as suggest so vigorously elsewhere), all it takes is for a tiny little update by you with no public oversight to own every server I have access to. How is that possibly improving security?!
- hosh 9y agoI have read through the FAQ and many of the comments on the thread. They seem rational to me. I have mixed feelings about this, mostly around the emotional inertia for changing something. On the other hand, I can see an immediate use-case for this for me. I use mosh to log into my cloud dev environment and since mosh doesn't support ssh-agent forwarding (and unlikely to ever to support it) ... this seems much a much better alternative.
- libeclipse 9y agoLooks cool, but I don't believe it's mature enough at the moment for me to use it. Will be keeping an eye on it though.
- vikeri 9y agoGreat stuff! Could there be an option to disable the notification for certain "less security critical remotes"?
- sleepychu 9y agoIs one of these repositories the server?
- tscs37 9y agoThis looks interesting but until Ed25519 on Android, importing existing keys and Paper Backups are supported it's a no-go for me. For some things I trust a paper backup in a fireproof safe over some nebulous cloud thingy on my phone. Atleast everything is open source, I'll favorite it and check back some time in the future.
- woodylondon 9y agoNice idea - played a bit. Any plans to add Linode.com ?
- xaduha 9y agoLooks like you're using pkcs11 instead of inventing your own stuff, so kudos for that at least. But I wish people would be aware of smartcards more, they are all around us, but sort of invisible and unnoticed. 1. But cheap blank "Java" smartcards, more or less disposable 2. Install this applet on it https://github.com/philipWendland/IsoApplet https://github.com/philipWendland/IsoApplet 3. Works with OpenSC
- j_s 9y agoIs it possible to use a chip/EMV credit card as an X.509 certificate? Let the credit card company know your private key (paranoid assumption; not necessarily true) & skip straight to step 3!
- xaduha 9y agoLook, I'm not an expert, I just dabble a bit. In theory there's no need for anyone to know your private key, it is generated on the card and kept there, unextractable. As I understand it there's nothing stopping credit card companies from allowing you generate your own keys on it (on a technical side that is), it just wasn't done AFAIK.
- j_s 9y agoI have a smart card so I have the reader, but when I put in my credit card it doesn't even appear as though it can read it. I would love to use my "always-with-me" credit card for home PC sign-on and whatever else but there's nothing out there on the integration. Any pointers would be appreciated!
- xaduha 9y agoTo read a bit of info about your credit card you can use this https://github.com/martinpaljak/GlobalPlatformPro https://github.com/martinpaljak/GlobalPlatformPro, it will output something like Card CPLC: ICFabricator: 4790 ICType: 5049 OperatingSystemID: 8241 OperatingSystemReleaseDate: 2218 OperatingSystemReleaseLevel: 1520 ICFabricationDate: 3086 ICSerialNumber: 06575696 ICBatchIdentifier: 6664 ICModuleFabricator: 4810 ICModulePackagingDate: 3086 ICCManufacturer: 1180 ICEmbeddingDate: 3086 etc I guess it's enough information to concoct some kind of 2-factor auth, but what is stopping you from promoting your real smart card into "always-with-me"? Or one of smartcards, since you can have many. NFC-capable phones can act as a card reader for contactless smartcards AFAIK, so that's something you can look into also.
- 0xCMP 9y agoIt'd would be nice if Kryptonite supported ssh clients on mobile devices too. i.e. On iOS there is the opensource Blink client. Not sure how the protocol would change, but it'd be nice if Kryptonite could store the keys in one place focused on securely storing the keys and then ssh clients can use them as needed. (Also for things like an iPad using a key on a phone)
- jorangreef 9y agoWould iTunes Sync or iCloud Backup include app data for Kryptonite (possibly including the private key)?
- elahd 9y agoAssuming Kryptonite does back up data to iCloud, there are two things to note: 1. iCloud backups are encrypted. 2. If you're not comfortable with #1, you can manually exclude an individual app from iCloud backups through Settings > Storace & iCloud Usage > Manage Storage (in the iCloud section). Click on your device in the Backups section. Turn off Kryptonite in the "Choose Data to Back Up" section.
- Corrado 9y agoWhat, if any, integration points do you have with Keybase.io? One of the things that I think Keybase got right is the sharing of public key information and it would be awesome if you guys could work together.
- agrinman 9y agoWe'd love to do an integration with keybase.io: i.e. add your Kryptonite SSH public key to your Keybase profile.
- jmuguy 9y agoSet this up earlier for github and a few servers. It's very convenient, and I like having the kr commands for adding the public key to whereever. As others commented, the licensing is important to get worked out
- V-eHGsd_ 9y ago> The private key is stored on your phone i'm reminded of theo deraadt's answer to a slashdot question back in the say about making a bootable openbsd firewall on a floppy. his response was along the lines of, "firewalls are supposed to be among the most reliable things. floppy drives are among the least reliable things."