4 ms·
Author here. The credentials are encrypted on-disk with a passphrase, so it wouldn't be trivial extract them, but yes it would be somewhat less secure than a ha
by cmdli 4y ago
Author here. The credentials are encrypted on-disk with a passphrase, so it wouldn't be trivial extract them, but yes it would be somewhat less secure than a hardware device. I would consider it similar in security to a local password manager. (Note: this software is in beta so I wouldn't yet use it for significant security operations)
Personally, part of the motivation for creating this was to find a middle ground between the most-secure hardware keys and the least-secure password options for authentication. I would argue that requiring users to have hardware is one of the main reasons we only see YubiKeys as a second factor, even though they benefits outside of being based in hardware (namely the lack of phishable passwords).
- pabs3 4y agoI hear that Apple is creating "passkeys" which are essentially what you have created; FIDO/WebAuthN that is implemented in software and are even syncable into the cloud.