age v1.1.0-rc.1: plugin and YubiKeys support
github.com
github.com
This also lets you use your shell's tab completion or even a fuzzy finder to list and select identities.
But perhaps age is better suited as a backend in other apps, especially Go apps. A good feature of PIV applet of Yubikey 5 is that it stores 24 keys. compared to 3 in OpenPGP (although any app including GPG could make use of those 24 slots).
What I am looking for these days is a back up tool that uses age. Can an app like restic use age as backend?
Note that not all 24 of those keys are suitable for age usage. The 4 main keys have specific usage definitions in the PIV specification that mean hardware tokens alter how those key slots behave. Only one of them (the KeyManagement slot) has a definition that allows encryption, and even that I was somewhat suspicious of overlapping with, as I couldn't predict how those existing keys were being used, and didn't want to support every possible key type that might be in that slot (which users likely wouldn't be able to alter).
age-plugin-yubikey avoids this complexity by only interacting with the 20 "retired" slots, which have no constraining definitions. (I am considering adding restricted support for the KeyManagement slot specifically for CAC card users who aren't allowed to add new keys to their cards [0], but this would be behind a default-off feature flag to keep the primary UX simple.)
A PGP keyring is a list of identities. Once you have verified an identity you can not be tricked into using the wrong encryption key for that entity. You can then be sure of the authenticity of any messages/files you get from that entity.
I get that it's out of scope and wouldn't be that hard at all to implement a wrapper that handles this, but without that functionality I find it much less enticing because I'm left to think about something that the other tool I use handles (and as you've noted, a lot more seriously too).
It had only the basic features you’d want for cryptographic agility.
During my reading, I came across age and wanted our business to use it, but it was too early to make that call across the entire business. It had only been released the previous year.
It also missed one crucial feature, which I think is the biggest miss with age: lack of support for AES-256 GCM.
I understand the arguments for not including it.
I also understand that if you want absolutely no serious adoption, it’s fine not to include it.
Why do you need AES ?
Age uses ChaCha20-Poly1305 which is more than good enough, and has the added benefit of being an algorithm that is optimised for software only implementation and doesn't need hardware support (e.g. AES-NI instruction set).
My biggest frustration with GPG is that it needs to have keys imported to do anything useful. I greatly prefer just storing the keys in the file system!
Related to that last point, Gentoo uses GPG to verify distfiles sometimes and it ends up creating a lot of "dummy" keyrings and throwing them away to circumvent this limitation of GPG! (I haven't dug too deeply into the code so it's possible that I am wrong here, but this is my current understanding)
My two primary issues with age that have prevented me from using it are that it doesn't use authenticated encryption (see links below) and that there is no way to encrypt/decrypt and make signatures with a single key pair (at least afaik). If I am encrypting files I want to be able to trust the contents of it fully, otherwise it's really not that useful for me personally!
Meanwhile, there is no worse format in the world when it comes to authentication than PGP, with the (ongoing!) saga of it's weird, unsound MDC.
>For public key cryptography, the notion of authenticated encryption becomes more complicated. I wrote a three-part blog post about it. There are public key authenticated encryption modes, such as NaCl’s box, but age doesn’t use one of those and instead opts for unauthenticated ECIES encryption (like JOSE’s ECDH-ES algorithm) using X25519. So while age uses symmetric authenticated encryption for the file contents, the symmetric file key is itself encrypted using an unauthenticated mode.
>it is completely insecure to pipe the output of age into another tool without independently establishing the authenticity of the file.
I disagree that it's outside of age's scope. One of the example use cases in the readme is piping age to another program such as tar.
This makes age (without minisign or whatever) useless and/or insecure for most people.
>you can’t simply use a static key pair with age to achieve authenticated encryption as age’s key-wrapping algorithm is completely insecure when used in this way
>an attacker cannot tamper with the encrypted ciphertext, but they can completely replace it with one of their own choosing
>it is completely insecure to pipe the output of age into another tool without independently establishing the authenticity of the file
Can you go into depth about why it's "grossly inaccurate"? So far you haven't actually explained why it's not correct, and these quotes seem to directly support everything that I have said.
Is there an issue with the authors analysis perhaps? Has age since then resolved any of this? I am curious what makes you disagree here.
I suspect that what you are arguing is mostly semantics about age using authenticated encryption during the symmetric phase of the whole process, but since the symmetric key is not authenticated that defeats the purpose as far as I can tell.
For YubiKey support specifically, my age-plugin-yubikey plugin handles encryption and ephemeral decryption (meaning that it connects to the YubiKey live, and thus has to treat e.g. "Once" PIN policies as "Always"). Once something like yubikey-agent has been extended to provide an age plugin, you could then take an age-plugin-yubikey identity and convert it into an agent plugin identity (so that the age client knows to invoke the agent's plugin for decryption rather than age-plugin-yubikey).
It looks like there are some caveats around Full Disk Encryption, and with use with M1 Macs.
Here's a guide which uses the PIV module with the newer Yubikeys. https://support.yubico.com/hc/en-us/articles/360016649059
For the cheaper U2F security keys (or older Yubikeys which do challenge-response stuff).. I've seen comments that had success using U2F for sudo/su, but not the login screen.
age -i =(pass my_age_key) ...