Live data from Hacker News

Yubico with new 4096-bit keys and gpg-agent for ssh authentication

trmm.net

31–40 of 51 posts

Re: Yubico with new 4096-bit keys and gpg-agent for ssh authentication

#32
Offtopic question:

Is there any FDE software that supports keeping decryption keys on a network server? You would still need to enter user authentication to obtain the decryption key of course.

Use case: We are a HIPAA environment, I want a hard drive to be useless if it is removed from the building.

Re: Yubico with new 4096-bit keys and gpg-agent for ssh authentication

#33

Offtopic question: Is there any FDE software that supports keeping decryption keys on a network server? You would still need to enter user authentication to obtain the decryption key of course. Use case: We are a HIPAA environment, I want a hard drive to be useless if it is removed from the building.

We use Checkpoint where I work and I am almost certain it does key escrow.

Re: Yubico with new 4096-bit keys and gpg-agent for ssh authentication

#34
post #9

Nitrokey[1] is about the same price as Yubico but has open source firmware & hardware . You might also know them as CryptoStick[2]. [1] https://www.nitrokey.com/ [2] https://blog.mozilla.org/security/2013/02/13/using-cryptosti...

This looks really neat. Anyone also use these? Thoughts? I might get myself one.

Edit: Also, does this have gpg-agent / ssh support?

Re: Yubico with new 4096-bit keys and gpg-agent for ssh authentication

#35
post #27
post #18

Looked at these last year but opted for smartcard and secure pinpad reader instead.

Can you provide links to what you chose instead?

I dunno about him, but I do something similar on one of my machines. I use an SCM SPR-532 USB reader with pinpad and an OpenPGP v2 smart card. More info and pictures here - https://grepular.com/Smart_Cards_and_SSH_Authentication

Re: Yubico with new 4096-bit keys and gpg-agent for ssh authentication

#36

Offtopic question: Is there any FDE software that supports keeping decryption keys on a network server? You would still need to enter user authentication to obtain the decryption key of course. Use case: We are a HIPAA environment, I want a hard drive to be useless if it is removed from the building.

I recently solved this problem using StrongAuth. We used SED disks instead of FDE software.

http://keyappliance.strongauth.com/

Re: Yubico with new 4096-bit keys and gpg-agent for ssh authentication

#37
Buy the one with smaller form factor. the device bends with very nominal pressure and if you are someone as me who works mostly on one device and need to move around a lot with it - unplugging and replugging the key is very cumbersome. You can leave the nano one in port and forget it until you need it in another device. My two cents from using a neo to store production ssh keys.

Re: Yubico with new 4096-bit keys and gpg-agent for ssh authentication

#38
post #27

Earlier quoted context omitted.

Can you provide links to what you chose instead?

I dunno about him, but I do something similar on one of my machines. I use an SCM SPR-532 USB reader with pinpad and an OpenPGP v2 smart card. More info and pictures here - https://grepular.com/Smart_Cards_and_SSH_Authentication

Where did you get the PGP card? Did you donate to become a fellow?

I've been thinking about it, but it's a bit confusing figuring out what cards are compatible and donating to the foundation is nice but a bit expensive.

Re: Yubico with new 4096-bit keys and gpg-agent for ssh authentication

#39

Are the github keys they sold cheaply compatible with 4096 bit keys? I'm loathe to buy another, considering i've got 3 already...

I picked up two of the github keys. Never did get them working under OS X. Plug them in and nothing, not recognized by any of their tools, no new keyboard recognized prompt, nothing. Anyone else have trouble with them on OS X?

Re: Yubico with new 4096-bit keys and gpg-agent for ssh authentication

#40
post #9

Nitrokey[1] is about the same price as Yubico but has open source firmware & hardware . You might also know them as CryptoStick[2]. [1] https://www.nitrokey.com/ [2] https://blog.mozilla.org/security/2013/02/13/using-cryptosti...

This looks really neat. Anyone also use these? Thoughts? I might get myself one. Edit: Also, does this have gpg-agent / ssh support?

I tried the pro model but went back to the FST-01 as it was too slow for RSA 4096 and doesn't support curve25519 for sign/auth.

But, yes, it does work with gpg-agent with ssh support.

Post reply on HN