4 ms·
> Neat, if you disregard the (justified? unjustified?) widespread suspicion of TPMs. Most of the TPM fears are about its secure booting features, about locking
by thomashabets 13y ago
> Neat, if you disregard the (justified? unjustified?) widespread suspicion of TPMs.
Most of the TPM fears are about its secure booting features, about locking in a machine to a certain OS or DRM code. This isn't using those features.
> If the attacker has access to that key, then they have access to your machine.
Not necessarily true. First of all they won't have access to you machine all the time. When you turn it off they won't have access to the key. Same when you improve your firewall rules (maybe).
I get a warm feeling from knowing that when someone logged in using a specific key, then a certain piece of hardware was involved in the handshake. Not "someone logged in", but "someone logged in using this exact laptop".
> It should be noted that ssh, gpg-agent, and OpenPGP smart cards already provide the capability to store an SSH key on a removable smart card.
Previously blogged about here: http://blog.habets.se/2013/02/GPG-and-SSH-with-Yubikey-NEO http://blog.habets.se/2013/02/GPG-and-SSH-with-Yubikey-NEO
> Of course, most modern machines come with a TPM (right? correct me if I'm wrong)
Not Macs.
> very few people have an OpenPGP smart card.
Yubikey NEO can be an option, since it uses USB.