The comparison table is wrong when it comes to Nitrokey Start / Gnuk. Keys are encrypted, it is 100% libre software, can be audited, auditing isn't harder than GnuPG.
-
-
Entering a passphrase directly on the device is another nice property of the Trezor Model T, but a traditional HSM can support that for encrypting keys and still wouldn't have the solid approach to recovery or the deniability from all passphrases leading to valid wallets/keys.
-
I'd really like to see other implementations of the same model they've designed. There are many other cryptocurrency wallets doing it but it's just as applicable to U2F, SSH and GPG which are also provided by a Trezor. I'd like to see alternatives with compatible implementations.
-
Another advantage is that the Trezor Model T has you confirm actions on the device for U2F, SSH, GPG, etc. It doesn't just have that for sending a Bitcoin transaction or verifying a receive address by showing it as text / qr code on the device. It has you confirm U2F/SSH/GPG use.
-
The disadvantage of the deterministic wallet approach is you can't use it to important and secure existing keys, so you need a mechanism for key rotation. Similarly, if you decide to change the passphrase, that involves key rotation since keys are derived from seed + passphrase.
-
It's how I'll be handling SSH, GPG and other keys in the future. The traditional HSM approach doesn't work for me because I need backups of the keys. For U2F, it's also silly you need recovery codes for each site. I have offline recovery for U2F as a whole with this approach.
End of conversation
New conversation -
-
-
Why? You can use a completely non-connected computer, even wipe or physically destroy it afterwards if needed. Risk only arises if there's an exfil channel available after the restore op.
-
It's an issue for the initial key generation rather than just recovery since you're forced to do it on a computer and trust that it's generating the keys properly due to needing to back them up onto cold storage. It's very difficult to wipe all state on a general purpose PC too.
- 4 more replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.