11 ms·
Nice! It is easier for me to have multiple SSH keys backed by my Yubikey than GPG keys (only 1 GPG key per Yubikey).
by berryton 4y ago
Nice! It is easier for me to have multiple SSH keys backed by my Yubikey than GPG keys (only 1 GPG key per Yubikey).
- nerdponx 4y agoI find it weird that GPG/PGP leans so heavily into "one key per person". Why shouldn't I be encouraged to have 2 or 4 or 10 identities if I want to? If my "web of trust" is diluted as a result, then that's on me (and I don't much care).
- upofadown 4y ago>I find it weird that GPG/PGP leans so heavily into "one key per person". It does? >Why shouldn't I be encouraged to have 2 or 4 or 10 identities if I want to? What is stopping you?
- lxgr 4y ago> It does? At least the OpenPGP smart card specification kind of does, yes. It uses a "single private key stored on the card" (ok, actually three keys) model, whereas FIDO (including SSH‘s security key implementation) uses key handles, which theoretically support an unlimited number of keys per authenticator.
- aborsy 4y agoA key handle seems to be the real private key encrypted with a static key from the hardware key. You can achieve that yourself, for example, using Pass. Encrypt theoretically unlimited number of password and secret keys with the master password in the hardware token.
- lxgr 4y ago> A key handle seems to be the real private key encrypted with a static key from the hardware key. It can be, but it‘s essentially just a binary blob. It can also be entropy to deterministically re-derive a private or secret key from an internal root secret, or just a primary key to look up that key or entropy within the token. > You can achieve that yourself, for example, using Pass. How? With a hardware token, you can only do what its protocol allows you to in terms of key derivation. That means that with a standard OpenPGP card, you will not be able to do key handle based key derivation, while with FIDO/CTAP you can. You could obviously develop your own OpenPGP-compatible hardware token standard, but you‘d only be able to use it with a patched version of GPG, GPG agent etc, but a big advantage of OpenPGP smartcards (and even more so FIDO/CTAP tokens) is that they are widely supported without requiring driver installation.