#yubikey

13 posts · Last used 10d

I just wanted to call out this guide: https://github.com/drduh/YubiKey-Guide If you're trying to set up hardware level security using yubikeys, it is invaluable. It takes some time and preparation, but the results are that you have a system where you can definitively say that your code is signed by you, your connections are authenticated as being yours, and nobody can use your digital identity but you. Even if you leave the YubiKey in the computer all the time, as long as you've turned on mandatory touch to unlock. It's really nice. #security #yubikey
0
0
1
0
One perk of working for Red Hat was the ability to use a self-managed OS. However, this is coming to an end due to compliance requirements. I'm not comfortable with having my personal private keys on a managed system, so I moved my SSH key, GPG key, and electronic signature certificate to a #YubiKey. And damn, it works nicely!
30
1
7
0
I set out last week to replace my #passwordmanager #gopass. My requirements: keys live on my #yubikey, unlocking one secret doesn't expose the whole vault, native #Wayland UX, per secret fingerprint/pin policy. Survey: severely lacking. I was not looking for a project, but the #linux desktop really needs this. To stay motivated I raised the bar: native #cosmic and #android too, learning #slint on the way. Not a webview. Secrets done right: constant-time and zeroized. Now we're cooking on gas!
3
2
2
0
Replying to

@moschehaus@social.moschehaus.com Made some progress this we. Most of the setup works: Clone a repo, list the recipients used by the repo and import the age identities in the #yubikey #PIV on both #cosmic and #android both using #slint.

The critical paths now work, next up:

  • Decrypt using the key in the PIV.
  • Prompt to import keys during setup.
  • Prompt to import their SSH key for cloning.

The first release will be a read-only vault you can use to unlock and audit secrets.

#Clav #passwordmanager

2
1
1
0
Ich werde dieses Jahr auf der #Froscon meinen Workshop zum Laptop absichern in einer aktualisierten Version halten: Wir bauen uns einen Congress-Laptop: #CachyOS härten für Einsteiger https://programm.froscon.org/froscon2026/talk/9bef50ee-9fb4-469d-85f0-bf5c224276eb/ Spannung, Spiel und Spaß u.a. mit Secure und Attested Boot, #TPM2 als Vertrauensanker, #HardenedKernel und #IOMMU, #USBGuard, #Firejail und #Yubikey Rechtzeitig zur Veranstaltung werde ich eine Anleitung/Doku zum nachlesen und mittippen veröffentlichen. #froscon2026 #froscon26 #security #hardening #linux @FrOSCon@bonn.social
0
0
0
0

A public project should not be credible only because it appears online.

This is why I am using ProofBundle for the projects I publish and discuss publicly, including the ones I present here on LinkedIn.

ProofBundle creates a portable cryptographic proof for a project snapshot.

It takes the files, builds a deterministic SHA-256 manifest, reduces the entries into a Merkle tree, and produces one Merkle root for the whole project state.

Then that root is bound to a signed author/custody claim.

ProofBundle can also use OpenTimestamps: the Merkle root and manifest hash are timestamped and anchored to public blockchains, without uploading the original project and without putting the contents on-chain.

So the proof has three layers:

  • integrity: SHA-256 hashes, manifest, and Merkle root
  • identity/custody: Ed25519 or OpenPGP signature
  • time evidence: OpenTimestamps blockchain anchoring

For signing, ProofBundle supports a default Ed25519 mode: modern, compact, and easy to verify.

It can also use a detached OpenPGP signature, including OpenPGP keys based on Ed25519. And for stronger key custody, OpenPGP signing can optionally be backed by a YubiKey, so the private signing key stays hardware-backed and non-exportable.

This is not copyright registration and it is not a legal shortcut.

It is technical evidence that:

  • this exact project state existed
  • these files matched this manifest
  • this Merkle root represented the snapshot
  • this key signed the claim
  • the timestamp evidence was

anchored through OpenTimestamps

  • the proof can be verified independently

Full technical note: https://www.gabrielesalati.eu/blog/proofbundle-verifiable-project-integrity.html

#ProofBundle #OpenTimestamps #Blockchain #OpenPGP #Ed25519 #MerkleTree #YubiKey #CyberSecurity #SoftwareEngineering #OpenSource

0
0
0
0
Konnte jetzt bei #Paypal den einen #Yubikey als Hardwaresicherheitsschlüssel hinzufügen, den anderen aber nur als OTP Gerät. Paypal scheint keine zwei Yubikeys zuzulassen. Ich kann also auch keinen weiteren Schlüssel hinzufügen. Und Passkey geht nur über den Device Dienst, bei Android gab es einige zur Auswahl (die Yubico App nicht), weil man auf Systemebene mehrere haben kann. Bei Apple nur "Password", was wohl der Nachfolger der Keychain ist. Schon seltsam sowas.
0
0
0
0
You've seen all posts