logoalt Hacker News

oigurshlast Monday at 12:45 PM1 replyview on HN

Can you explain your motivation around gpg-agent and yubikey little more, please? So the private key can't be copied elsewhere?


Replies

tadfisherlast Monday at 6:51 PM

Yes, that's the motivation.

These days I would explore the TPM option, but I'm worried that has less legal teeth than a physical key if I'm in a law enforcement situation.

There's also practicality; I really, really don't want to tell my boss that TSA or whoever had access to the company git repositories and databases for X minutes or hours, and that's sidestepped by checking a bag with the Yubikey (wastes their time) or mailing it to the destination (needs a warrant).