7 ms·
Hey HN! We've built a way to generate an SSH key on your phone and use it from your computer such that the private key never leaves the phone. We were inspired
by 4kevinking 9y ago
Hey HN! We've built a way to generate an SSH key on your phone and use it from your computer such that the private key never leaves the phone. We were inspired by the threat model of USB HSMs like the Yubikey and set out to build a free, public source, and easier to use BYOD alternative. Looking forward to your questions!
- falcolas 9y agoThe Yubikey (as in generate and store SSH keys on the Yubikey) is not exactly a hard to use option. It's not as nicely packaged, but quite functional. EDIT: I'd love to talk about this, if someone has a differing opinion. Once set up, it was dirt simple to use.
- StavrosK 9y agoI am of the same opinion. I added the library in my SSH config and now SSH will just use the yubikey, if it's plugged in. The only problem is that I haven't been able to find an agent supporting all of (gnome keyring for persistent passwords, ed25519 keys, the yubikey).
- newman314 9y agoSome questions & comments: * Can you have multiple private keys (site specific?)? * Does the Android client support ed25519 keys or is it iOS only? * Please modify your curl statement to be something like how Honeycomb does it (that is include a checksum test). https://honeycomb.io/docs/connect/nginx/ https://honeycomb.io/docs/connect/nginx/
- 4kevinking 9y ago1) We are planning to support multiple private keys, but currently only support a single key pair. 2) Android doesn't yet support ed25519 but it is coming. 3) We would consider something like this but the question is how that checksum test itself is served. We'll definitely look into improving this. The curl script itself does check the hashes of the installed binaries downloaded from github.
- tptacek 9y agoMultiple private keys are more important than you might think, because Github won't let you use the same key in more than one account, so everyone who has more than one Github account and wants hardware tokens has to have multiple hardware tokens.
- 4kevinking 9y agoI didn't realize that, thanks for letting us know! We're actively working on this
- dolmen 9y agoAs you seem to use multiple GitHub accounts with SSH, you might be interested by the ssh_config tricks that I implemented in github-keygen https://github.com/dolmen/github-keygen/ https://github.com/dolmen/github-keygen/
- pquerna 9y agoI love the transparency of having your source on Github, but the license ambiguity isn't ideal when revealing this to the world: We are currently working on a new license for Kryptonite. For now, the code is released under All Rights Reserved. https://github.com/KryptCo/kr#license https://github.com/KryptCo/kr#license Soon as I see that, I've got to close the tab, so does anyone who cares about IP. (disclaimer: i'm a co-founder of ScaleFT)
- dudus 9y agoIs proprietary code even allowed on GitHub?
- shimon_e 9y agoYes
- stordoff 9y agoYou grant some rights to other users of GitHub, but I'm not seeing anything that prevents proprietary code: > If you set your pages and repositories to be viewed publicly, you grant each User of GitHub a nonexclusive, worldwide license to access your Content through the GitHub Service, and to use, display and perform your Content, and to reproduce your Content solely on GitHub as permitted through GitHub's functionality. You may grant further rights if you adopt a license. https://help.github.com/articles/github-terms-of-service/ https://help.github.com/articles/github-terms-of-service/ To anyone more versed in US law than me, what usage specifically does "use, display and perform your Content" permit?
- Ajedi32 9y agoHow's that ambiguous? The code is proprietary; all rights reserved. Seems like they're planning to change that in the future, but in the meantime the existing license seems pretty clear to me.
- jaytaylor 9y agoFor one of the main repos: https://github.com/KryptCo/kr https://github.com/KryptCo/kr 57% Go 40% Rust First time I've seen them paired together in the wild like this, very cool!
- 4kevinking 9y agoThanks! We love Go for its SSH support and Rust for its dylib / crypto libraries.
- BlackLotus89 9y agohttps://news.ycombinator.com/item?id=14121780 https://news.ycombinator.com/item?id=14121780 on go ssh security And what is the use of this when it runs on a platform that is an active target for every intelligence agency in the world with irregular updates, regular security problems and other problems like preinstalled spyware and so on? Nice idea, but only if the phone was a platform you could trust.
- sp0ck 9y agoThose two languages are lowering attack surface by huge factor ! :) What a amazing combination.
- rileytg 9y agolicense :( this exact thing is on my devs teams backlog. if you figure out a good license it would be AMAZING for us.
- j_s 9y agoGPLv3 should be enough for an app; AGPL adds additional protection for server-side/self-hosted projects. https://softwareengineering.stackexchange.com/questions/142012/using-an-agpl-3-0-licensed-library-for-extra-functionality-in-an-ios-app https://softwareengineering.stackexchange.com/questions/1420... The MuPDF app is available under AGPLv3+. https://itunes.apple.com/us/app/mupdf/id482941798?mt=8 https://itunes.apple.com/us/app/mupdf/id482941798?mt=8 You will catch some flak for discouraging free commercial re-use. If you see your app or portions of it as more of a library for others to use then LGPL is an option that requires reciprocity. In an unusual case, a "lax" license was recommended for the reference Ogg/Vorbis audio codec implementation: https://lwn.net/2001/0301/a/rms-ov-license.php3 https://lwn.net/2001/0301/a/rms-ov-license.php3
- stephenr 9y ago> AGPL adds additional restrictions for server-side/self-hosted projects Fixed that for you.
- laken 9y agoAny chance of a UWP/Windows Phone app in the future?
- cynix 9y agoCan't seem to create both an RSA and an Ed25519 key.
- 4kevinking 9y agoCorrect, we currently only support one key, but multiple key support is in the works!
- cynix 9y agoAny plans to support FreeBSD?