Show HN: Cocert: split your private keys securely amongst untrusted network
github.com
github.com
Seems like a neat project.
> If you can store the password securely can you not then also store the private keys securely?
You don't have to store the private keys securely. On the contrary, you can store your private keys publicly, if the decryption password strong enough.
If you want to decrypt keys in the pipeline, of course your decryption keys still need to be stored securely. Which is why I added some KMS providers in the use-case diagram. [1]
[0] https://github.com/theupdateframework/go-tuf/blob/master/enc... [1] https://raw.githubusercontent.com/Dentrax/cocert/main/.res/u...
From among the designs that looked decent to my untrained eye (not a cryptographer) were that of Apple's and Signal's [0]. The thing they had in common was they wanted to gatekeep attempts to brute-force (one half of the) the secret they stored on behalf of the user, via either binding them in HSMs or secure enclaves.
Keybase instead do what they call TripleSec [1], which seems like a cheaper solution compared to Apple's / Signal's, and relies on multi-cipher encryption scheme to thwart brute-force attempts.
One area that I've been increasingly looking at is OPRF (Oblivious Pseudo Random Functions) [2] and the use-cases it may enable, especially in replacing the HSMs or secure enclaves whilst retaining similar properties against brute-force attacks.
[0] https://news.ycombinator.com/item?id=21838413