Hacker News new | ask | show | jobs
by qbasic_forever 1951 days ago
The auto lock on device removal with udev rule would be the same idea, in fact you could use any USB device like a basic flash drive if you wanted. Changing PAM's login to use the device for login would require a bit more device-specific stuff--I'd search around to see if Safenet already provides a module to drive PAM auth.
1 comments

This pam_usb fork can be used to set up any USB for authentication: https://www.linuxuprising.com/2021/02/how-to-login-with-usb-...
This are PKI tokens, like smartcards. I would like something tied to a certificate and private key on the device. That would be unforgeable