logoalt Hacker News

jdmoreiratoday at 11:24 AM2 repliesview on HN

These things should be offline / resilient first right?

Smartcards / YubiKeys.

Never understood the logic for these to be centralised / online.


Replies

xorcisttoday at 11:34 AM

PKI works offline until you realize you need to handle revocations.

For this and related reasons, such as enforcing protocol upgrades, most smartcard systems end up permanently online.

show 1 reply
consptoday at 11:29 AM

Revocation.

show 1 reply