Hacker News new | ask | show | jobs
by kfreds 1372 days ago
Hi! Interesting. Which company do you work for?

Yes, that'd be possible. I don't know how webauthn works, but if it relies on ECC you could probably do ECDH between all security keys you wanted to carry your master key, and then use the combined ECDH values as the master key.

1 comments

I work at a consulting firm in Stockholm, my remark about competition was solely from a user/hacker standpoint. My day job is more about security in the higher levels of the stack :-)

Cool! It was a while since I looked in the standards, but I think there definitely is support for using ECC based algorithms.

Looking forward to follow your journey!

Ah, OK! :)