7 ms·
Hardware Touch, Stronger SSH
- olivermuty 9mo agoFiller pr jippo fluffer article aside, anyone tried to self host ubicloud lately? A year and a half ago it was super cumbersome, wondering if I should give it a new try now.
- antonkochubey 9mo agoOn Apple Silicon devices with macOS 26+, SSH keys can be natively stored in the Secure Enclave, protected via TouchID: https://news.ycombinator.com/item?id=46025721 https://news.ycombinator.com/item?id=46025721 It only supports sk-ecdsa-sha2-nistp256 key format, however that is widely supported currently.
- XiS 9mo agoBeen using ed25519-sk with Yubikey for a few years now. Key is stored in KeepassXC and loaded in my SSH agent upon unlock. It makes my SSH key pretty portable across devices
- throwawayqqq11 9mo agoMy approach aswell. Lock down ssh-agent and restrict its usage as much as possible. Securing your keys is also very reasonable but it cant silence this naging voice in the back of my head that keeps reminding me of a compromised ssh-agent or shell, whenever i authorize privileged actions.
- Almondsetat 9mo agoYou can also do something similar with any computer that has a TPM. It's unfortunate that people don't really know about it, but I guess the tools available aren't that user friendly
- Foxboron 9mo ago> It's unfortunate that people don't really know about it, but I guess the tools available aren't that user friendly This is my cue. https://github.com/Foxboron/ssh-tpm-agent https://github.com/Foxboron/ssh-tpm-agent
- Sublevel5169 9mo agoThank you for sharing!
- sebazzz 9mo agoSSH using GPG Yubikeys and git signing using GPG was quite a process to set up on Windows a few years ago. Not something I'd want or know how to repeat. Hopefully things have improved in the mean time.
- heavyset_go 9mo agoYou can use SSH keys for signing now, so you don't need GPG at all.
- simon04 9mo agoUsing a Token2 based id_ed25519_sk_rk key, I found very helpful to configure a different `pushurl` in `.git/config`. This allows to pull via HTTPS w/o a hardware touch. [remote "origin"] url = https://github.com/freeCodeCamp/devdocs.git pushurl = git@github.com:freeCodeCamp/devdocs.git
- ComputerGuru 9mo agoGitHub dropped http authentication so this only works for public repos (not that the UX or security of http auth for git is nice). Can git be configured to use different keys for push and pull? (You can obviously use different upstreams, but thats not as elegant.) Most git servers let you specify read vs read-write privileges (aka “deployment keys”) so you could use one key to pull updates that doesn’t need touch and another key to push (which does).
- baobun 9mo agoYou configure separate entries in your ssh conf. Host gh-auth Hostname github.com Identityfile blah User git pushurl = gh-auth:freeCodeCamp/devdocs.git
- Arrowmaster 9mo agoGitHub did not drop http auth. They prefer you use http instead of ssh. What they dropped was auth using your account name and password. You need to use a token as your password or use an extra tool like their cli client to setup auth (but it sucks if you have multiple accounts).
- solatic 9mo agoThis is how you handle it as an individual developer, but in a corporate environment things get real difficult, real fast. You need to set up your VMs and Git host to only trust certificates signed by an SSH certificate authority, and you need to work with users to submit the public key from the hardware-backed key to IT (controlling the CA) to get the public key signed and a certificate issued. Establishing trust when dealing with remote workers is hard unless you have both the budget and leadership patience to pay for overnight shipping, and even then, most people don't have access to tamper-proof packaging. Furthermore, for SSH CA support, GitHub requires Enterprise Cloud, GitLab requires Premium and self-hosted instances are not supported. Would love to hear more from people getting this successfully set up at scale in corporate environments. I've seen big companies with lots of InfoSec talent not even attempt this.
- connicpu 9mo agoI can't speak to actually setting it up, but where I work we have an IT-provided yubikey ssh-agent that handles getting all that stuff set up, and we just paste the public key from our individual yubikeys into our authorized ssh keys with our on-prem-hosted bitbucket server. However almost everyone I know quickly gets sick of touching the yubikey for every git remote operation and just generates their own local SSH key to use for git since doing so is not forbidden. It's definitely not High Security, but since our git is on-prem and can only be accessed from within the corporate VPN the risks are probably lower than if we were using something shared on the public internet.
- solatic 9mo ago> almost everyone I know quickly gets sick of touching the yubikey for every git remote operation and just generates their own local SSH key to use for git since doing so is not forbidden Yes, that's the exact problem at hand. If you generate your own local SSH key, the private key sits on the disk, and it can be stolen by malware (see article). I'm asking how people set up the controls such that only hardware-based keys are signed by the CA.
- deleted 9mo ago[deleted]
- talkingtab 9mo agoIn my opinion only, Yubico has done no favors to the Fido by their marketing. A result of trying to make Yubikey synonymous with Fido, it has become unclear what Fido does. And as a result of how they market their keys, decisions Fido keys are presented with a cost of $20 - $60. Why $60, for a simple Fido key? Because for $60 you get not only Fido, but Flippo, Froggo, x.6s8o and more-o. The result is that most people know the name Yubikey, but don't really know Fido, or what it is. On Amazon if you search for Fido you get mostly Yubikeys. There were other brands, but Yubico appears to have snuffed them. At one point there was an open source version that worked just as well as a name brand. As for value? If you are a big corporate type this is the cat's meow. But otherwise? What other hardware is $60? A Raspberry Pi 4? I can get little cheap USB thingies from China at 6 for a dollar. I am not pointing at Yubico as they have done well making profits from corporations. Rather the Fido Alliance. Looking at the Fido Alliance provides a first pass at answering the question "Who Benefits?" https://fidoalliance.org/overview/leadership/ https://fidoalliance.org/overview/leadership/ Perhaps it is fair to ask "What benefit" as well. Corpocracy. You gotta love it.
- machinationu 9mo agowhile you are right, security is generally not cheap. you can get that $5 china fido key, but are you sure it's you who owns it? I was recently looking for a security key, and eventually I did pay the yubico tax, because saving $20 by getting another one seemed unwise given the stakes.
- gruez 9mo ago>you can get that $5 china fido key, but are you sure it's you who owns it? Seems like a moot point because it'd be very difficult for a rogue fido key to exfiltrate data. I'd be far more concerned about random chinese IOT gadgets, which most people don't have a problem with.
- the8472 9mo agoCouldn't they ship pre-compromised? Storing the RNG seed and private key at the factory.
- machinationu 9mo agoHow will this work with agents?
- shim__ 9mo agoThat's the neat part, it doesn't
- PunchyHamster 9mo agoNow that's just incorrect
- PunchyHamster 9mo agoYou just get a prompt. Problem is really there is no good way for the prompt to have the name of actual app that asked when it is forwarded.
- guerby 9mo agoI bought several "Security Key NFC by Yubico": their cheapest model, no storage or fancy stuff. My personal strategy is to use keys generated this way: ssh-keygen -t ed25519-sk Rules: - A generated key never leave the machine it was generated on. - ssh agent is never used - ProxyJump in HOME/.ssh/config or -J to have convenient access to all my servers. - DynamicForward and firefox with foxyproxy extension to access various things in the remote network from my local machine (IPMI, internal services, IoT, ...) - On the web no passkey, only simple 2FA webauthn. My understanding is that more features including "storage" means more attack surface so by avoiding it you're 1/ more secure 2/ it's cheaper. White paper on passkey says their security is equal to the security of the OS (Microsoft Windows ...) so I avoid passkeys.
- PunchyHamster 9mo agoThe more expensive one works as smart card so you can both generate and keep the key as hardware only. Works for SSH and GPG too
- smileybarry 9mo agoThe generated FIDO keys with "[...]-sk" are hardware-only too, the "key" you load is only an "identifier" associating the onboard passkey, allowing you to add it on multiple computers but still requiring the FIDO key present to use[1]: > ssh-keygen(1) may be used to generate a FIDO token-backed key, after which they may be used much like any other key type supported by OpenSSH, so long as the hardware token is attached when the keys are used. FIDO tokens also generally require the user explicitly authorise operations by touching or tapping them. > [...] > This will yield a public and private key-pair. The private key file should be useless to an attacker who does not have access to the physical token. After generation, this key may be used like any other supported key in OpenSSH and may be listed in authorized_keys, added to ssh-agent(1), etc. The only additional stipulation is that the FIDO token that the key belongs to must be attached when the key is used. IMO the baseline Security Key ($20) series is now enough, unless your setup uses PGP, legacy SSH that doesn't support these key types, or if you're using a real certificate for e.g. code signing. 1: https://www.openssh.org/txt/release-8.2#:~:text=The%20private%20key%20file%0Ashould%20be%20useless%20to%20an%20attacker%20who%20does%20not%20have%20access%20to%20the%0Aphysical%20token. https://www.openssh.org/txt/release-8.2#:~:text=The%20privat...
- tasn 9mo agoThis is how I've been doing it: https://stosb.com/blog/using-openpgp-keys-for-ssh-authentication/ https://stosb.com/blog/using-openpgp-keys-for-ssh-authentica... Slightly different as I generate a PGP key on the computer and then load it to the Yubikey, which means I can have backup keys with the same secret keys. I never really got "touch to use" working though, if anyone knows how to do it with GPG keys I'd really appreciate it!
- ratdragon 9mo agossh-add -c (confirm) can somehow mitigate the "misuse of ssh-agent in the background" the article is talking about
- clait 9mo agoCould someone please explain to me why this would be better than storing the key with 1Password and biometric authentication?
- btreecat 9mo agoShameless link to my own blog where I use a yubikey to store my SSH private key, a long with some advice for use in macos and Linux. https://stephentanner.com/ssh-yubikey.html https://stephentanner.com/ssh-yubikey.html Hopefully someone finds it useful. The biggest issue I ran into was when folks wrote some tools that rely on ssh sock auth to automate connection to remote boxes. Not fun if you have to tap for every box.