6 ms·
I use Secretive to authenticate to SSH (including GitHub) with my Mac’s TouchID. Feels like this is (almost) as secure, while being more convenient (no extra ha
by dochtman 5y ago
I use Secretive to authenticate to SSH (including GitHub) with my Mac’s TouchID. Feels like this is (almost) as secure, while being more convenient (no extra hardware required). Of course it is a Mac-only solution.
- viraptor 5y agoOther systems allow something similar using TPM. Both Linux and Windows can use a hardware non-exportable key with SSH that way. It doesn't allow for the touch verification on use, but it's still better than having a file in the disk. Security scale would be: - key in a file - TPM - touchid - hardware gpg/SSH key - hardware u2f key
- mercora 5y agoare keys in the TPM really securely stored and accessed? can i trust those to only be used by myself by i.e. providing a password or similar? i also think touchid should rank even lower because its likely somewhat easy to forge.
- viraptor 5y agoTPM keys are not accessible once imported or generated. You only get access to operations like encrypt/decrypt on them. Those are also normally accessible only by the root user, so you use some kind of proxy with an extra step (like a password) to make them available to the user. I'm not sure what you mean by touchid being easy to forge.
- mercora 5y agoso that does mean once i have access to the computer the keys are somewhat free to use. thus i am authenticating the device not the user which is kind of an important distinction... IMHO this is not as secure as storing the key encrypted on a drive where its only accessible using a passphrase. It is just harder or maybe even impossible to exfiltrate the key but you really don't need to do that in order to use it. i might be wrong though. My remark about touchid came from the fact that fingerprint scanning is inherently insecure because it is trivial to fool most devices into thinking you got a matching fingerprint using something that was touched and left a mark and some glue.
- tialaramex 5y ago> thus i am authenticating the device not the user which is kind of an important distinction.. It is very unlikely that the actual threats you face make this "an important distinction". If you don't have 24/7 bodyguards, it's time to be realistic with yourself that in fact "I got drunk and clicked something dumb" or "That wasn't a real email from FedEx, what was I thinking?" are much bigger threats than "A covert team picked the lock on my condo and then while I was asleep they modified my MacBook to help them break into my GitHub account". > fingerprint scanning is inherently insecure because it is trivial to fool most devices into thinking you got a matching fingerprint Because biometric security in these scenarios is local the bad guy needs to steal the device first. Again, it is very unlikely your threats look like that. Real crooks who steal devices like MacBooks or iPhones will sell them to some dodgy bloke not try to impersonate you and break into your GitHub account before you invalidate the keys.
- mercora 5y agothese are valid points and of course everything you do to improve your security posture should somehow be related to your real threat model. However, OP was implying TPM might be more secure then an encrypted key on a disk which i disagree with for the mentioned reasons.
- cryptonector 5y agoNo, ninjas won't be breaking into your home to install malware on your devices, but the maids at the hotels you stay at might! That is known as the Evil Maid threat. Yes, hotels tend to have safes in the room that will fit smallish laptops but those can be reset by... the hotel anyways. This is also a problem at work where you might leave your laptop on your desk at your cubicle.
- viraptor 5y ago> once i have access to the computer the keys are somewhat free to use Once you have access and either root or pass whatever extra authentication the access requires. > storing the key encrypted on a drive where its only accessible using a passphrase The extra failure mode here is that someone can copy the key and crack your password offline on their own time. > using something that was touched and left a mark and some glue. At that point a camera catching your password should also be a potential threat. But yeah, if that's something you're realistically worried about then it's not a great solution for you.
- comboy 5y agoDoes Mac store fingerprint or does only Mac's hardware have access to it? In other words - if your Mac breaks down, does backup save you or do you also need to have some alternative way to auth?
- mrw 5y agoFrom Apple's support page [1] (Secure Enclave section near the bottom): > The chip in your device includes an advanced security architecture called the Secure Enclave, which was developed to protect your passcode and fingerprint data. Touch ID doesn't store any images of your fingerprint, and instead relies only on a mathematical representation. It isn't possible for someone to reverse engineer your actual fingerprint image from this stored data. It's pretty easy to make use of Touch ID for `sudo` authentication, for instance [2]. [1]: https://support.apple.com/en-us/HT204587 https://support.apple.com/en-us/HT204587 [2]: https://news.ycombinator.com/item?id=26302139 https://news.ycombinator.com/item?id=26302139
- justincormack 5y agoYou can't back it up. For ssh keys for eg github this is fine, you just configure a new one as you dont need the ssh key to log in (eg I have password and multiple u2f tokens). For ssh to say servers you might want another key setup, you could have an offline software key, or multiple computers.