Earlier quoted context omitted.
There is NitroKey[0], which seemed to me like a good alternative to Yubikey, but I haven't ordered either yet so I can't say I have first-hand experience. But much luck if you decide to go with it, something I'm looking more and more into, especially since I too use password-store and it would be good having an easier to use setup that is still secure. [0] https://www.nitrokey.com/
Nitrokey claims on their homepage that the firmware of the Storage version of NitroKey can be updated by software. This seems to mean that there's someone out there with a key that can sign arbitrary code that can be loaded as an update and gains access to the crypto material on the device.
The GNU Privacy Handbook (1999)
11–17 of 17 posts
Re: The GNU Privacy Handbook (1999)
#12Wow, this is so old (1999) it's terrible. It recommends generating DSA keys. Interesting as a historic artefact, but please don't follow this guide, search for something more recent.
Re: The GNU Privacy Handbook (1999)
#13Wow, this is so old (1999) it's terrible. It recommends generating DSA keys. Interesting as a historic artefact, but please don't follow this guide, search for something more recent.
I'd be curious to read what article is better, so you who search, please share your findings
Re: The GNU Privacy Handbook (1999)
#14For a much more gentle (and illustrated) introduction do public-key encryption, GnuPG and how to use it with email (Thunderbird + Enigmail), see FSF's Email Self-Defense: https://emailselfdefense.fsf.org/ Tactical Tech's Security in-a-Box has more detailed, step-by-step, multiple platform guides for the same tools: https://securityinabox.org/en/guide/thunderbird/windows https://securityinabox.org/en/guide/thunderbird…
Re: The GNU Privacy Handbook (1999)
#15first page: "You must also choose a key size. The size of a DSA key must be between 512 and 1024 bits". Definitely do not follow this guide nowadays :D
Re: The GNU Privacy Handbook (1999)
#16Re: The GNU Privacy Handbook (1999)
#17Earlier quoted context omitted.
Nitrokey claims on their homepage that the firmware of the Storage version of NitroKey can be updated by software. This seems to mean that there's someone out there with a key that can sign arbitrary code that can be loaded as an update and gains access to the crypto material on the device.
I had a look through their instructions and I'm not sure if there is a signing process that happens. You have to enable firmware access from the app, and then it's a bog standard DFU flash to load the new firmware.