Earlier quoted context omitted.
while you are right, security is generally not cheap. you can get that $5 china fido key, but are you sure it's you who owns it? I was recently looking for a security key, and eventually I did pay the yubico tax, because saving $20 by getting another one seemed unwise given the stakes.
>you can get that $5 china fido key, but are you sure it's you who owns it? Seems like a moot point because it'd be very difficult for a rogue fido key to exfiltrate data. I'd be far more concerned about random chinese IOT gadgets, which most people don't have a problem with.
Hardware Touch, Stronger SSH
51–53 of 53 posts
Re: Hardware Touch, Stronger SSH
#52Earlier quoted context omitted.
>you can get that $5 china fido key, but are you sure it's you who owns it? Seems like a moot point because it'd be very difficult for a rogue fido key to exfiltrate data. I'd be far more concerned about random chinese IOT gadgets, which most people don't have a problem with.
Couldn't they ship pre-compromised? Storing the RNG seed and private key at the factory.
However yes a very limited entropy in the private key is much harder to detect especially because on this kind of device you can't see the private key directly.
Re: Hardware Touch, Stronger SSH
#53Earlier quoted context omitted.
You're paying for brand and the fact they make key exfiltration very hard. Getting the key out of rpi4 will be trivally easy if someone stoles it, not so much for hardware key. I am surprised that competition didn't kept them in check, we're using them for more than a decade and the price just keeps slowly creeping in.
Run-off-the-mill smart cards have had non-extractable keys for decades. They only cost cents in manufacturing.