Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Interesting one, thanks!!

I'm kinda hoping Yubi come out with a version 6 with many more "passkey" CTAP2 slots too. Because I don't only use FIDO functionality but I heavily use the OpenPGP slots as well. Not for email but for other things (file encryption, password manager, SSH). Not planning to change any of that to fido any time soon either.



Small clarification: SSH functionality is a part of FIDO stack (if you meant ecdsa-sk & ed25519-sk )


Yeah, but without resident keys you’ll have to carry a file containing the key handle around with you from computer to computer (where you want to use the Yubikey-resident SSH key). And if you ever lose the file, your key is lost too!

This is because SSH doesn’t have a centralized RP model that’s kind of implied in FIDO and WebAuthN for non-resident keys.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: