Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I was mostly responding to: "But they're pretty marginal against the kinds of attackers who will target SSH keys."

I am arguing it is not all that marginal. If the only non 0-day way into production is via ssh to a bastion host with a touch-based hardware token then their lives are more than marginally harder than an on-disk key.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: