Hacker News new | ask | show | jobs
by tanderson92 2416 days ago
Oh that's great, alleviates my concerns, which was like, how do you know you're even asking the yubikey to do key generation rather than a malicious actor generating a private key and placing it on the yubikey. Thanks!
1 comments

If you don't trust the hardware, then don't use it. I'm not sure what solution would fit your threat model, other than building your own.
I didn't say I distrusted the hardware, I said the very opposite. I said I didn't see how, before this attestation feature, you could guarantee your computer software even asked the hardware to generate the key.