4 ms·
All of this signing is only useful if someone is actually checking or enforcing those signatures, otherwise it's just LARPing. Being able to sign commits with
by Androider 5y ago
All of this signing is only useful if someone is actually checking or enforcing those signatures, otherwise it's just LARPing.
Being able to sign commits with your SSH keys makes signing actually useful, because it enables a new workflow that developers will use:
- You give every dev on your team a Yubikey
- They generate an ed25519-sk key that only resides on the Yubikey, no software required as it works out of the box with both openssh and GitHub
- They upload the public ID of the key to GitHub, same as before
- You enforce commit signature verification for your GitHub org. You're done, no need to install any software, everything Just Works.
You now have:
- No private keys on developers machines, rendering all types of supply chain attacks like NPM stealing your .ssh files ineffective
- Enforced 2FA for everyone without any hassle
- Every commit signed by developers, enforced and with no developer overhead. Checks a lot of boxes for those SOCs and ISOs.
- entropie 5y ago> They generate an ed25519-sk key that only resides on the Yubikey, no software required as it works out of the box with both openssh and GitHub How does this work? Can you like me a ressource?
- Androider 5y agoYou run `ssh-keygen -t ed25519-sk -O resident`, and that's it, no additional software required as of OpenSSH 8.2. If you have an older model Yubikey you can try ecdsa-sk instead. For more details, see: https://github.blog/2021-05-10-security-keys-supported-ssh-git-operations/ https://github.blog/2021-05-10-security-keys-supported-ssh-g... https://www.yubico.com/blog/github-now-supports-ssh-security-keys/ https://www.yubico.com/blog/github-now-supports-ssh-security...
- dec0dedab0de 5y ago- No private keys on developers machines, rendering all types of supply chain attacks like NPM stealing your .ssh files ineffective Would it be able to get the key from the usb device? Or does the hashing happen on the device itself with the private key never exposed? If that's how it works, that would be awesome, but would a malicious program be able to sign something as you, instead of stealing the keys? I'm going to look into this more and maybe recommend it at work.
- coldacid 5y ago>Would it be able to get the key from the usb device? Or does the hashing happen on the device itself with the private key never exposed? If you could extract the key, you probably have access to the intelligence resources of a very large nation. With hardware security dongles, the key remains on the dongle; you pass your data in and it passes the signature (or encrypted data) back out.