3 ms·
Yes but do mind hardware bugs that affected YubiKeys such as https://magicofsecurity.com/roca-critical-vulnerability-in-infineon-security-chips/ https://magicof
by Leace 7y ago
Yes but do mind hardware bugs that affected YubiKeys such as https://magicofsecurity.com/roca-critical-vulnerability-in-infineon-security-chips/ https://magicofsecurity.com/roca-critical-vulnerability-in-i...
Also I'd strongly encourage generating encryption subkey in software (offline, air-gapped machine) and then copying it to Yubikeys. If you lose your Yubikey (or mistype 3 times the PIN) you wouldn't be able to decrypt your secret data.
- trishankdatadog 7y agoWe're aware of hardware vulns like ROCA (we used to check the exact version of the YK, now we support only the major version 5). We're taking the risk anyway because the benefits of having the private keys generated and stored entirely on the YK is entirely worth it. We're also not primarily using the YK to encrypt messages. If continuing to decrypt shared messages in the future is critical, I'd personally look into HSMs which offers key-wrapped backup.
- Boulth 7y agoDo you know a HSM that use key wrapping and are OpenPGP compatible? I've seen only X.509 compatible ones.