4 ms·
For _using_ WebAuthn, Linux without a TPM has the option of using a hardware key like a Yubikey or Nitrokey, or a virtual authenticator like what 1Password prop
by sebk 4y ago
For _using_ WebAuthn, Linux without a TPM has the option of using a hardware key like a Yubikey or Nitrokey, or a virtual authenticator like what 1Password proposes here: https://www.future.1password.com/passkeys/ https://www.future.1password.com/passkeys/
For _syncing_ WebAuthn passkeys, then virtual authenticators that sync over the wire like 1Password above is the only option. Using virtual authenticators means that your key material is in-memory alongside the OS and all running apps. That's why it's so critical that OSs expose pluggable sync fabrics; so that vendors like 1Password, or even YubiCo, can implement sync fabrics that roam through whatever hardware the current platform happens to have available.
- alyandon 4y agoHrm... how would these master keys get stored securely on Linux without a dedicated TPM? It seems that all these methods seem to want to desperately replace "something I know" with "something I have" that can break, get lost/stolen, etc. That is not a very enticing scenario for me.