Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If you could manage to modify Signal so it's keys were stored on the security key, and the user had to tap each time they log in, that would be far more valuable than GPG.


As cool as that would be its probably not doable because gpg doesn't support curve 25519, which is what signal uses for its authentication keys. So either needs gpg decides to support the curve or hardware keys need to explicitly support either signal or the 25519.


GnuPG supports Curve 25519: https://gist.github.com/jmgrosen/5e646d6a6624c0d0e45f241be21...

However, perhaps you're referring to the OpenPGP Smart Card spec, which does indeed lack support for Curve 25519 and EdDSA.


Even though Gnuk supports them: https://debconf17.debconf.org/talks/162/

I wish the spec would be updated to include them...


Can confirm, I use a NitroKey Start (which is a gnuk token) with that curve. I have used it for GPG signing/encryption and SSH authentication without any issues.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: