10 ms·
Show HN: GPG on macOS and YubiKey
- trishankdatadog 7y agoMain contributor here! Let me know if you have questions.
- pera 7y agoThis is pretty useful to me, thanks! I specially like how small the code is: it means I can easily audit it :) Maybe you should edit the title of this submission and add "Show HN" (https://news.ycombinator.com/showhn.html https://news.ycombinator.com/showhn.html).
- trishankdatadog 7y agoDone, thanks!
- girzel 7y agoThis looks like it's MacOS only, right? Surely it wouldn't be too hard to get the same stuff working for Linux?
- trishankdatadog 7y agoYes! We are primarily a macOS shop, so I don't see us supporting Linux very much, but you are more than welcome to fork :)
- fabioyy 7y agoAny issues using Catalina? mine shows Error: No YubiKey detected!
- trishankdatadog 7y agoNo, but try unplugging the YubiKey and trying again. Also, the script officially supports only YubiKey 5, but I've heard that 4 works if you remove the code that checks the version.
- deleted 7y ago[deleted]
- dkanejs 7y agoNice repo. For those starting from scratch with a YubiKey I always recommend this guide: https://github.com/drduh/YubiKey-Guide https://github.com/drduh/YubiKey-Guide Then they know how this stuff works and how to fix it when it breaks.
- trishankdatadog 7y agoThat guide is great --- really helped me out when I started! Then I realized why no one uses GPG in practice: this stuff is way too hard even for security experts. That's why I believe in making things as easy and usable as possible w/o sacrificing security.
- tanderson92 7y agoBut you already succeeded at sacrificing security, because there is no note about performing key generation not in an internet-connected machine, ideally a live cd / usb image boot. From the drduh guide: > It is recommended to generate cryptographic keys and configure YubiKey from a secure operating system and using an ephemeral environment
- trishankdatadog 7y agoTo the best of my knowledge, if you trust the YubiKey firmware, and assuming that it behaves correctly, the private keys are generated on the YubiKey itself, and cannot be exported.
- tanderson92 7y agoThis is assuming the binary you are running on your internet-connected computer is doing what you expect.
- trishankdatadog 7y agoThe GPG applet is inside the YubiKey and running entirely on there, to the best of my knowledge. Update: new YKs with new firmware are apparently able to provide proofs that the keys were generated on hardware. https://news.ycombinator.com/item?id=21523354 https://news.ycombinator.com/item?id=21523354
- oil25 7y ago> For usability while balancing security, cache PIN for at most a day. https://github.com/DataDog/yubikey/blob/master/gpg.sh#147 https://github.com/DataDog/yubikey/blob/master/gpg.sh#147 This statement has no effect when using Yubikey - the PIN is cached by the key itself and it will remain unlocked indefinitely until it's physically unplugged. See https://dev.gnupg.org/T3362 https://dev.gnupg.org/T3362
- trishankdatadog 7y agoInteresting. This hasn't been my experience, so not sure what's going on yet...
- microcolonel 7y agoSlightly related: Anyone know why Google Chrome (not upstream Chromium, nor any derivative) is the only browser on Android that implements WebAuthn as intended? Do they implement it as a proprietary component?
- trishankdatadog 7y agoNo, sorry.
- samwestdev 7y agoIs signing every commit really that useful?
- trishankdatadog 7y agoIf you care about who produced your source code, yes.
- rgoulter 7y agoI think "sign every commit useful?" is less about whether signing is useful, and more about the trade-off of signing every commit vs just signing a tag on a commit. Signing every commit is going to make it a mindless task. It's easier to be vigilant when signing if you sign less frequently. What trade-offs should be considered?
- philsnow 7y agogit config --global commit.gpgsign true this turns commit signing on for every commit, you don't have to explicitly sign commits as a separate step. the criticism I've always heard of this practice is, what do you do with those signatures? github displays a little widget showing that the commits are signed, but beyond that I don't think it cares which public key they were signed with, so it's not really helping anything.
- rgoulter 7y ago> this turns commit signing on for every commit My understanding is: Entering a key passphrase each time is going to be annoying without providing benefit over just signing some git tag. Leaving the key unlocked in an agent is going to be somewhat less secure than requiring the key to be unlocked on every use. > github displays a little widget showing that the commits are signed, but beyond that I don't think it cares which public key they were signed with, so it's not really helping anything. As I understand it, "verified" means it's either a commit made on GitHub's website with that user signed in, or the commit was signed with one of the keys associated with that user's profile. I guess for the case of "I only trust commits signed by a certain key", you'd need to use a different GitHub profile.
- eximius 7y agoI've been very pleasantly surprised by how easy it was to get everything set up on NixOS: ``` programs.gnupg.agent = { enable = true; enableSSHSupport = true; }; services.udev.packages = [ pkgs.yubikey-personalization pkgs.libu2f-host ]; services.pcscd.enable = true; environment.shellInit = '' export GPG_TTY="$(tty)" gpg-connect-agent /bye export SSH_AUTH_SOCK="/run/user/$UID/gnupg/S.gpg-agent.ssh" ''; ``` The only surprise I had was that I forgot to tell gpg to trust the imported key after I imported it. Combine this with GoPass... its the start of something good :)
- equalunique 7y agoAre you using Gnome? I remember when this was impossible to get working on Gnome for a couple of releases. Hoping that's fixed now.
- eximius 7y agoI'm using awesome wm. What was the problem with gnome? I vaguely recall a problem with polkit or something.
- m3nu 7y agoPersonally I mostly use it for SSH via PKCS11. I found that simpler than GPG because it's already integrated with SSH. Still looking forward to SSH supporting U2F (some day).
- ecesena 7y agoIt's here: https://marc.info/?l=openssh-unix-dev&m=157259802529972&w=2 https://marc.info/?l=openssh-unix-dev&m=157259802529972&w=2
- ssklash 7y agoThat day may be rather soon: https://news.ycombinator.com/item?id=21417182 https://news.ycombinator.com/item?id=21417182
- mzi 7y agoIt landed 1 november[0] [0]: https://marc.info/?l=openssh-unix-dev&m=157259802529972 https://marc.info/?l=openssh-unix-dev&m=157259802529972
- new_realist 7y agoIs there a similar guide for TouchID?
- jtaft 7y agoIt's not polished, but here's a vagrant box which can provision Yubikey's PGP and PIV applications. Additional hardening can be performed. https://github.com/justintaft/yubikey-gpg-piv-provision https://github.com/justintaft/yubikey-gpg-piv-provision
- rmoriz 7y agoYubikey as a second factor for macOS login is still not possible, right?
- trishankdatadog 7y agoI don't think so. That's what TouchID is for, and we are thinking of storing signing keys in that secure enclave in the future.
- Leace 7y ago> Optional: verify public key on Keybase. For organizations publishing employee keys via Web Key Directory can also be an additional signal that the key is trustworthy. It's also quite simple: for example exporting the key 5C090ED7318B6C1E (binary, not armored) and putting it on this exact URL: https://datadoghq.com/.well-known/openpgpkey/hu/964aj6q73iatngoya1q7qs4r6utpmb4g https://datadoghq.com/.well-known/openpgpkey/hu/964aj6q73iat... is enough to discover the key using e-mail address. This post goes into more detail: https://spacekookie.de/blog/usable-gpg-with-wkd/ https://spacekookie.de/blog/usable-gpg-with-wkd/ WKD is used by Linux distros (ArchLinux, Gentoo, Debian...) and kernel.org itself: https://www.kernel.org/category/signatures.html#using-the-web-key-directory https://www.kernel.org/category/signatures.html#using-the-we... as well as some OpenPGP sites (e.g. ProtonMail).
- trishankdatadog 7y agoGood idea, will make a note, thanks!
- matheusmoreira 7y agoUsing a hardware token to protect the subkeys is important but it is also necessary to protect the primary key by keeping it offline. The best method I know is to store it on paper with the help of paperkey: http://www.jabberwocky.com/software/paperkey/ http://www.jabberwocky.com/software/paperkey/ The tool also supports a raw output mode which can be piped to a QR encoder. 4096 bit RSA secret keys fit in binary QR codes and they are much easier to use compared to manual data entry. Current versions of zbar can't decode binary data in QR codes properly. I've sent some patches that fix the problem but they haven't been reviewed yet. Hopefully it will be possible to automate this process with zbarcam soon.