4 ms·
I'd add to this list that in 2023 you should be securely storing your key in a HSM. On Mac, that's easy to do via the Secure Enclave: https://github.com/maxgoe
by walth 3y ago
I'd add to this list that in 2023 you should be securely storing your key in a HSM.
On Mac, that's easy to do via the Secure Enclave:
https://github.com/maxgoedjen/secretive https://github.com/maxgoedjen/secretive
- b112 3y agoIt's never enough for you walth, is it? I used to use an easily memorizable password, but you said that was wrong, and set me straight. Now my password is so complex, I have to rely upon a 3rd party service, that keeps getting hacked. Then you insisted I use keys. After, you became irate if I left the keys on my work dir. Now you want me to lug around a 2U HSM appliance?! For shame!
- deleted 3y ago[deleted]
- touisteur 3y agoCan't / shouldn't lug 'em around, some of these boxens have shock, temperature, movement failsafes. Anti tampering you see.
- deleted 3y ago[deleted]
- touisteur 3y agoSee today's HN link for an example https://tches.iacr.org/index.php/TCHES/article/view/9290/8856 https://tches.iacr.org/index.php/TCHES/article/view/9290/885...
- h2odragon 3y agoPhysical access only. The server is air-gapped. And there's a big dog chained to the desk beside it. Biometric security, you see: if you don't smell right to Brutus, you don't get to log on. Look at our security rituals from an outside view: we sure do seem to spend a lot of time propitiating our idols of one kind or another.
- pxc 3y ago> Now you want me to lug around a 2U HSM appliance?! If you don't need a certified HSM that generates keys on device (and you don't, right? You can generate keys on a ramdisk from live media with no persistence and no/encrypted swap), you can use basically any PGP smartcard, including nice little USB ones like Yubikey and NitroKey. And even if you do you can get a little USB HSM.
- aidos 3y agoFor people using 1Password you can get it to act as an agent to lookup keys directly in your vaults. Again, great integration on a Mac where you can use your fingerprint each time the key is required.
- Foxboron 3y agoI've been hacking on `ssh-tpm-agent` which allows you to create or import TPM sealed keys. This is practical as it prevents key extraction and it has dictionary attack protection which allows you to have 4 digit pins instead of passphrases to protect your private keys. https://github.com/Foxboron/ssh-tpm-agent https://github.com/Foxboron/ssh-tpm-agent Currently hacking up better support for `HostKeyAgent` and `HostKey` for `sshd`.