An Advanced Intro to GnuPG
begriffs.com
begriffs.com
Now I learn there's something called GnuK but Google leads me to an obscure doc on building it yourself.
Until there are better options out there, I guess I'll stick to my Yubikey NEO
I guess they have gotten a lot of flack for not being fully open source but in my experience most people are OK with this.
https://developers.yubico.com/ykneo-openpgp/SecurityAdvisory...
I think they catch more flack because of the switch than they would have if they had been completely proprietary the entire time! (Even though the original open source applet couldn't be trusted completely since it ran on a proprietary runtime, the same way many do not trust open source Android software on phones due to proprietary cellular hardware.)
https://www.yubico.com/2016/05/secure-hardware-vs-open-sourc...
That being said I think the main objection to the yubikey is that they're using closed source software on the key. I'm not sure I really get the objection to be honest, in the end even if the soft is open source you have to trust them to actually flash that software on the key and not inserting hardware backdoors in the first place.
I highly recommend to every power user out there to get a GnuPG smartcard. It's convenient, secure, you can use it to sign and/or encrypt anything (email, files, passwords, git commits...), you can use it as an SSH key through GPG agent etc... It's well worth the ~50 euros it costs for the peace of mind it provides.
Hopefully it'll make PGP more popular and make it possible to actually send encrypted emails. I can't remember the last time I've received one myself...
I bought an Open PGP Card instead! https://www.g10code.com/p-card.html
You still have to buy your own card reader, and any card readers on the market aren't as small as the Yubikey... but it's a fantastic device and I love mine to death.
Note: the yubikey actually uses the open pgp card inside of it (which the actual implementation from the chip supplier is hardware-closed-source, although the reference architecture is open). The nitrokey too. They technically all have closed source with the BasicCard that runs inside them! With that in mind the secret-sauce of the yubikey is also closed source, where there's no secret sauce around your OpenPGP Card to be closed source.
I suppose nowadays 2048bit is more than enough but I like the extra safety and "future-proofness" of a 4096bit key.
The older versions of the card only supported 2048bit keys. The 2.0 version and above support 4096 :)
I personally generated my RSA4096bit key on the card!
https://sc4.us/hsm/ $75 | https://news.ycombinator.com/item?id=12053181
https://trezor.io/ $99 | https://news.ycombinator.com/item?id=10795087 (not much on HN)
https://www.floss-shop.de/en/security-privacy/13/openpgp-sma... €16.40 (OpenPGP Smart Card v2.1; 4096-bit keys)
https://www.fidesmo.com/fidesmo/about/privacy-card/ €15 (NFC only; recommended by the terminated SIGILANCE OpenPGP Smart Card project; 2048-bit keys)
--
The Mooltipass is intended for passwords but may support reading and writing small binary blobs, eg. encryption keys. AFAIK (as of August 2016) it wouldn't attempt to protect the private key / implement encryption.
https://www.themooltipass.com/ $79 | https://news.ycombinator.com/item?id=11983563
For U2A two-factor auth I use a little Yubikey that is dedicated just for that and fits comfortably on a keychain. https://www.yubico.com/products/yubikey-hardware/fido-u2f-se...
git config --global user.signingkey <your_pub_here>
git config --global commit.gpgsign true