logoalt Hacker News

Joel_Mckaytoday at 5:38 AM3 repliesview on HN

People don't need an extra supply-chain failure mode to consider, and CVE proved these dongles are mostly security theater. Likewise, the recent Coinkite user key prediction breach certainly wasn't cool for folks that lost their holdings. =3


Replies

Antirust3743today at 5:48 AM

Wrong cve and a side channel attack doesn't mean these dongles are useless. It would have stopped the firefox team's ai from commiting their subkey ;)

eptcykatoday at 6:12 AM

Storing the secret on a hardware token will most certainly help with not committing into source control.

show 1 reply
perching_aixtoday at 6:57 AM

> these dongles are mostly security theater

...as opposed to? What's your criteria for "non-security-theater"?

show 1 reply