4 ms·
> If you generate the keys off of the token you can never be 100% sure "no one else has a copy of this key", which should be at least somewhat distressing. Eh.
by tokenizerrr 9y ago
> If you generate the keys off of the token you can never be 100% sure "no one else has a copy of this key", which should be at least somewhat distressing.
Eh. I use a laptop with no local storage nor network booted off a read-only USB stick, and for good measure I wipe the USB stick after I'm done.
- KGIII 9y agoI've stared at your post, for at least five minutes. I've read it at least a dozen times. I can't figure out if you're being facetious or serious.
- rthille 9y agoBecause he wipes (writes to) the read-only USB stick? (The one that's had the firmware replaced with BadUSB, and which he then sticks in some other piece of hardware where it takes control of the machine and uploads his private key?
- KGIII 9y agoThe whole laptop, no memory, no network, etc... Just for this. I'm not sure if they are serious or if they really do so. If they do, that's quite some dedication to security.
- mcpherrinm 9y agoI work with keys used to move hundreds of millions of dollars. The effort to have an air gapped network is definitely worth it. I certainly don't do that for the keys I use to access my home computer though. Security is economics: what's it worth to attack you?
- KGIII 9y agoAh! That makes more sense. The closest I've come is working on an isolated network in a secured environment. I can't be specific, but I'm pretty sure the data I worked with had very little comparative value.
- tokenizerrr 9y agoIt's an old laptop. Instead of throwing it in the trash, I kept it around.
- tokenizerrr 9y agoNot sure what you mean. The USB stick gets mounted as read-only on boot, so while technically you could write to it, this does not happen. The key never gets written to the USB stick, and is only kept in memory, sent to the wired printer as an QR code, and of course the Yubikey. I then wipe the USB just because, but there is no real point in doing so. The largest vulnerability here would be the printer having some kind of memory, since BadUSB is a myth.