Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
4kevinking
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
4kevinking
9y ago
fish shell should be working now, let us know if you have any other issues!
32.
▲
by
4kevinking
9y ago
Correct, we currently only support one key, but multiple key support is in the works!
33.
▲
by
4kevinking
9y ago
I think you may have misunderstood our architecture. SMS doesn't play any role in Kryptonite and all communication between the phone and computer is encrypted and authenticated. Check out a full explanation of the architecture here: h
34.
▲
by
4kevinking
9y ago
Thanks, will fix this asap. We have tested on bash, zsh, and fish on macOS but it seems we missed an edge case. I'll follow up with your ticket.
35.
▲
by
4kevinking
9y ago
The current version is designed for hosted services like GitHub, redeployable infrastructure, and servers to which multiple people have access. We totally understand your use case and are actively working on implementing transferring a key
36.
▲
by
4kevinking
9y ago
Point taken. Unfortunately when you touch the key you still can't verify exactly what you are approving.
37.
▲
by
4kevinking
9y ago
That is correct. We will also soon release a way to copy a key from one device to another by scanning a QR code.
38.
▲
by
4kevinking
9y ago
I didn't realize that, thanks for letting us know! We're actively working on this
39.
▲
by
4kevinking
9y ago
We do the hashing ourselves so that it's easy to use any hash function in the future. If you create a Keystore key but decide to use a hash function you didn't specify at generation time, it will be rejected by the API.
40.
▲
by
4kevinking
9y ago
Thanks! We love Go for its SSH support and Rust for its dylib / crypto libraries.
41.
▲
by
4kevinking
9y ago
The attack surface may seem smaller for USB tokens, but storing the pin for say a Yubikey allows malware to use the key without restriction. Also, these USB devices don't have a UI, so you never know what you are actually approving, i.
42.
▲
by
4kevinking
9y ago
Yep! Just type 'kr me' to print your public key, or 'kr copy' to copy it right to your clipboard.
43.
▲
by
4kevinking
9y ago
Indeed, (encrypted) requests pass through SQS/SNS with credentials owned by us. We can see the amount of traffic, but not any of its contents or who sent it.
44.
▲
by
4kevinking
9y ago
1) We are planning to support multiple private keys, but currently only support a single key pair. 2) Android doesn't yet support ed25519 but it is coming. 3) We would consider something like this but the question is how that checksum
45.
▲
by
4kevinking
9y ago
Kryptonite allows you to use SSH on your computer, but authenticate with a private key protected on your phone. It doesn't require any changes to the server, just the Kryptonite app and our workstation software.
46.
▲
by
4kevinking
9y ago
No -- we treat every communication channel as untrusted. All communication between the phone and computer is encrypted with session keys established when you pair by scanning the QR code in the terminal. Check out our architecture post for
47.
▲
by
4kevinking
9y ago
Any user-level application on your computer can read the SSH key -- you'll never know if it's used or sent off somewhere. Even passphrase encrypted keys are vulnerable. Check out this blog post for a deep dive on our threatmodel a
48.
▲
by
4kevinking
9y ago
Hey HN! We've built a way to generate an SSH key on your phone and use it from your computer such that the private key never leaves the phone. We were inspired by the threat model of USB HSMs like the Yubikey and set out to build a fre
49.
▲
Show HN: Kryptonite – a new home for your SSH private key
(krypt.co)
338 points
by
4kevinking
9y ago
|
219 comments
50.
▲
by
4kevinking
10y ago
> If the machine is silently compromised, moving the private key one step away doesn't matter much; kryptonite will serve the signature regardless, and the attacker can cherry pick the active session keys. Yes, it's a partial b
51.
▲
AMEX Phisher Leaks Thousands of Victim IPs
(medium.com)
2 points
by
4kevinking
10y ago
|
0 comments
52.
▲
AMEX Phisher Leaks Thousands of Victim IPs
(medium.com)
3 points
by
4kevinking
10y ago
|
0 comments
53.
▲
Show HN: |Ears| Bass Boost, EQ Anything in Chrome
(chrome.google.com)
2 points
by
4kevinking
11y ago
|
0 comments
54.
▲
Ears: Bass Boost, EQ Anything in Chrome
(chrome.google.com)
1 points
by
4kevinking
11y ago
|
0 comments