logoalt Hacker News

nine_klast Saturday at 3:08 AM2 repliesview on HN

I agree that age + minisign comprise a much neater stack that does basically everything I would need to use PGP for.

Neither of them supports hardware keys though, as much as I could see. OTOH ssh and GnuPG do support hardware keys, like smart cards or Yubikey-like devices. I suppose by the same token (not a pun, sadly) they don't support various software keychains provided by OSes, since they don't support any external PKCS11 providers (the way ssh does).

This may reduce the attack needed to steal a private key to a simple unprivileged infiltration, e.g. via code run during installation of a compromised npm package, or similar.


Replies

some_furrylast Saturday at 6:31 AM

> Neither of them supports hardware keys though, as much as I could see.

https://github.com/str4d/age-plugin-yubikey

nine_klast Saturday at 6:19 AM

BTW apparently age has plugins that allow to use FIDO2 and TPM for cryptography.