OpenPGP master key on Nitrokey Start
blog.josefsson.org
blog.josefsson.org
It is by far the most comprehensive guide on using a YubiKey as a SmartCard for storing GPG keys. I used this a few years ago and it helped clear up any confusion I had about getting the most out of my Yubikey 5 NFC.
Pgp’s most valuable use case is still establishing a digital identity toehold. The PGP key that is used to sign the commit, is also used to SSH to git server, is also used to sign the code review comments, is also used to sign the build binaries.
I’m hoping some day there is website authentication integration via passkey or the like.
The closest thing to a binding identity in the PGP ecosystem is OpenPGP's "verifying keyserver," which issues a challenge to a submitted PGP key's claimed email address. But that isn't a very strong proof of identity, and it doesn't prevent anybody from claiming to be anybody else in the broader PGP ecosystem.
This is why Facebook has a real name policy for example.
With the move to federated systems in commercial hands (log in with Facebook, Google etc) this only becomes harder to escape.
I am quite knowledgeable about PGP but I have no idea what this means.
I can assume Linux and a good chance FreeBSD will have no issues with this device. I am curious about the other *BSDs though.
Nitro keys are semi open source. Other than that, any advantage?
I ordered a Nitrokey 3C NFC 2 years ago, never heard from them until a week ago where they said they shipped it (I'll believe it when I receive it). I tried to contact their support once to kindly ask if I still existed in their database, they answered that I should read the blog in a rude way (which did not even answer my question).
They were claiming 2 years ago that they had many features (my understanding was "almost compares to Yubikey"), and I realized recently that it was not only not true, but in those 2 years they haven't reached feature parity (not even remotely).
So... feel free to order a Nitrokey to support them (I did, and my hope is that it will get better), but if you want something that works today, go for Yubikey.
The main limitation of the Yubikey is that the firmware is closed source and potentially even backdoored. Otherwise the construction and features of Yubikey are pretty good.
About a year after they changed it though there was a huge vulnerability in the Yubikey where it failed to actually check the pincode making the security useless. Which proved locking the firmware was a bad idea IMO. They ended up having to replace tons of them which could have been updated. I was hoping they'd bring updatable firmware back but they didn't.
For such reasons, I have been searching for alternatives. It seems other products have other issues.
And Librem Key fully relies on FLOSS.
https://forums.puri.sm/t/librem-key-practical-usage-scenario...
Lacks FIDO, and curve 25519.
openssl s_client -connect blog.josefsson.org:443 < /dev/null 2>/dev/null | openssl x509 -fingerprint -sha256 -noout -in /dev/stdin
sha256 Fingerprint=AC:6A:41:71:DE:1C:B6:93:F0:63:56:D6:12:72:B3:27:B2:A7:C9:3F:86:4D:D9:55:63:B9:CB:CA:F6:38:83:70
This [2] may also be related. If you go to about:config and search for "security.ssl.enable_ocsp_must_staple" is it set to true? OCSP stapling offered, not revoked
OCSP must staple extension supported
[1] - https://www.ssllabs.com/ssltest/analyze.html?d=blog.josefsso...