5 ms·
Now you have a centralized single point of failure. While the ease of use is inherently obvious with the implementation, if/when it does fail you will have to f
by jas- 5y ago
Now you have a centralized single point of failure. While the ease of use is inherently obvious with the implementation, if/when it does fail you will have to fall back to public key/password auth anyways.
- blueflow 5y agoWhich failure mode do you mean? The CA is accessible via offline means. I can walk to it and sign me a new keypair.
- jon-wood 5y agoWhat happens when the building the CA is in burns down?
- BenjiWiebe 5y agoScan printed QR codes of your private key that you had backed up off-site.
- tomrod 5y agoThat's actually pretty brilliant.
- danuker 5y agoProvided you keep said papers away from prying cameras in a verifiable way, that is. For more inspiration, check out the Glacier Protocol. https://glacierprotocol.org/ https://glacierprotocol.org/
- tomrod 5y agoThanks for the heads up! I wish I'd thought about this when playing with bitcoin a few months after launch and amassing an integer value larger than zero. That wallet died with the hard drive.
- aspenmayer 5y agoPlease tell me you still have the hard drive. There’s a chance for recovery, and I have some experience in this area if you want some tips. Step 0 is always keep your drives for future recovery attempts.
- tomrod 5y agoIt was dumped many, many years ago while BTC was still a novelty paying for pizza in the thousands BTC per. I went to see if I still had a backup of the wallet with a USD:BTC spike a few years back and it was gone. Life goes on, even when sad things happen :(
- AitchEmArsey 5y agoThink of it this way: by starving the supply of that one bitcoin, you have contributed in some small way to the eventual loss of all bitcoins through similar events - speeding up the rate at which the world can move on from this silly fad.
- krnlpnc 5y agoddrescue may be of interest if you still have the disk. That's `dd` for broken disks. It keeps a log of data it couldn't read, and can keep trying to read it indefinitely, it even supports a save state and can resume trying again later. I've recovered filesystems from several failed disks using it. It's not fast though!
- xxpor 5y agoThe extreme version of this is using an HSM, and putting one in a safe deposit box.
- politician 5y agoIdeally, k-of-n key shards, stored in safety deposit boxes.
- blueflow 5y agoThe CA is in a gpg-encryped secrets store (pass) and has a password on itself, so it can be backupped like normal data to an off-site location.
- hamburglar 5y agoAlso, this doesn’t apply to most real scenarios (especially not “how I run my personal stuff” type scenarios), but is a fun one to contemplate: what happens when your customer has requirements that specify all keys (including root signing keys) to be rotated at a certain point in the future? Having a process for this is an interesting challenge.
- remram 5y agoThe CA is a key, not a network service.
- tptacek 5y agoCentralized single points of control are a basic goal of corpsec. They trade availability for security. The alternative model of individual SSH keys is theoretically more highly available, but has many single points of security failure.
- jas- 5y agoPlease enlighten me on the ‘many single points of security failure.’
- benlivengood 5y agoSign with two or three CAs, and have sshd accept any of them.