4 ms·
No, I'm not. I've got a bunch of yubikeys locked in lockboxes when they're not in use, serving as trust anchors for internal PKI, but also using certificate log
by GauntletWizard 2y ago
No, I'm not. I've got a bunch of yubikeys locked in lockboxes when they're not in use, serving as trust anchors for internal PKI, but also using certificate logging. If one is compromised, there's a short window until it's known, and access to the box has a very small group of people. My threat model does not include "Insider under the watchful eye of two other insiders"
- wannacboatmovie 2y ago> My threat model does not include "Insider under the watchful eye of two other insiders" Some Mastodon infosec grifter is going to name this "Insider Triple Threat".
- deleted 2y ago[deleted]