Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

For scenarios like this, where the hardware is untrusted, Yubikey type devices are really the only solution (where the device can present as a user input device, and provide the necessary string secret). Everyone else can use a password manager.

EDIT: If you're on an untrusted device, should you really be putting secrets into it? Maybe not!



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: