Hacker News new | past | comments | ask | show | jobs | submit login

Most workflows utilizing OpenPGP cards (like the Yubikey) encourage better key hygiene. Generally you'd create a certification key which lives offline 100% of the time, with a subkey issued to the Yubikey. This means your offline key can persist for a very long time while you can safely rotate the day to day subkey.

Unfortunately while these workflows are encouraged, the tooling doesn't exist to make it a trivial operation for folks not familiar with proper key hygiene.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: