3 ms·
One of our engineers, Paddy Steed, wrote a series of articles on how we each use a Yubikey for SSH, UTF 2FA, and access to 1Password on shared machines when we
by EngineerBetter 9y ago
One of our engineers, Paddy Steed, wrote a series of articles on how we each use a Yubikey for SSH, UTF 2FA, and access to 1Password on shared machines when we pair-program. The SSH key is generated on the Yubikey, so it never touches your machine's filesystem.
http://www.engineerbetter.com/blog/yubikey-all-the-things/ http://www.engineerbetter.com/blog/yubikey-all-the-things/
http://www.engineerbetter.com/blog/yubikey-ssh/ http://www.engineerbetter.com/blog/yubikey-ssh/
http://www.engineerbetter.com/blog/yubikey-static-secret/ http://www.engineerbetter.com/blog/yubikey-static-secret/
http://www.engineerbetter.com/blog/yubikey-2fa/ http://www.engineerbetter.com/blog/yubikey-2fa/
- OJFord 9y ago> The SSH key is generated on the Yubikey, Then FYI you should check, if you haven't already, the version of yubikey you have and replace it if necessary: https://www.yubico.com/2017/10/infineon-rsa-key-generation-issue/ https://www.yubico.com/2017/10/infineon-rsa-key-generation-i...
- als0 9y agoThis flaw only affected generated RSA keys, ECC keys should still be OK. Yubikey provided an excellent service for replacing their products when I went through them. However, I hear the story is quite different if you bought one via Amazon.
- Promarged 9y agoBut OpenPGP applet on Yubikeys cannot use ECC keys (no generation, no import). PIV applet can use ECC keys (but that's not covered in the attached article).
- OJFord 9y ago> This flaw only affected generated RSA keys, And only those of 2048b or fewer. > Yubikey provided an excellent service for replacing their products when I went through them. However, I hear the story is quite different if you bought one via Amazon. I bought from Amazon; requested a replacement directly, great service as you say, it didn't matter where I'd bought it originally.