←back to thread

637 points h1x | 1 comments | | HN request time: 0.47s | source
Show context
csomar ◴[] No.29208799[source]
Ledger/Trezor have solved this since ~2016. I have a Ledger that has a private key inside and using a small open source tool (https://github.com/romanz/trezor-agent) I can SSH into machines, sign random data and Github commits and FIDO authenticate into several websites. All of that and knowing that these devices offer some of the best security out there.
replies(2): >>29208982 #>>29209129 #
1. stavros ◴[] No.29209129[source]
FIDO2 is even better because SSH supports it natively, so there's no setup at all.