That makes me sad :( Does anyone know if that's a SE limitation, or the app's?
That makes me sad :( Does anyone know if that's a SE limitation, or the app's?
[0]: https://www.yubico.com/support/security-advisories/ysa-2017-...
I tried to look up the info, but the only thing I found was this: "But because its backing storage is physically part of the Secure Enclave, you can never inspect the key’s data."
https://developer.apple.com/documentation/security/certifica...
That means that it get stored in SE instead of your computer's hard drive. Also, Apple have instructions to clean Secure Enclave if you're going to sell your macbook pro with touchid.
Basically treat this the same as you would a physical 2fa token.
Without an export it could maybe be one key in a multisig.
That's also why it only generates one kind of key. It's a black box that spits out public keys.