Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Your computer can in theory get owned up without you losing your SSH or VPN keys, even if your keystrokes are logged.


Get owned = SSH is hikacked = I don't need your keys and can run any commands on your behalf.

This thing might protect from keyloggers but useless against proper malware that just waits for you to authenticate.


If your SSH private key is on the Yubikey then you will not lose your private keys. Even in the case of U2F, the attacker will not figure out your U2F private keys or even all the places you are registered.


His point, which is correct, is that you'll persistently lose access to your server anyways, because a backdoored SSH client is almost as bad as a compromised key. I use a Y4 for SSH, but it's good to be clear-eyed about the limitations.


Like everything, it's useful against some things and not against others. For some people, hardware SSH keys are worth the effort. For others, not.


In my opinion it's not worth the effort (and certainly not $50). It makes marginally +X harder to exploit yet marginally +X inconvenient to use = typical security through obscurity.


You've lost me at "security through obscurity".


My bad, it's not what classic "through obscurity" means. Instead I meant something that makes exploitation more "obscure" (you need to be prepared to hijack a server vs simply leak the key).


what makes it attractive to me is that it's actually much more convenient to use than a password.


It really is, but there is no need for hardware. Software based auth would be the same




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: