3 ms·
I've configured gpg to use keys from "smart cards" before, and didn't really fall in love. After the setup, things worked ok, but there were a few limitations
by codys 8y ago
I've configured gpg to use keys from "smart cards" before, and didn't really fall in love.
After the setup, things worked ok, but there were a few limitations that made me more happy with just having the key on my computer.
The primary was that I had no way to validate that the key material was encrypted at rest, and no documentation even appeared to make claims about how the key material was stored. My setup used a fairly long PIN to replace what would have been a fairly long password for decrypting the key material stored on my computer. I wasn't really comfortable with using something simpler as a PIN.
It may be the case that I could have leaned more on the hardware for security and told myself that the limit to the number of password attempts should allow for a shorter PIN to be used. But I was looking for something that I could add as another layer to my existing process, rather than something that replaced it.
At the end of the day, using a smart card to store key material just made it harder for me to reason about the security of the key material itself due to the increased number of unknowns. And it was more inconvenient.