Comment on What can we learn from the matrix.org compromise?parentComments−nine_k7yHow about using hardware tokens instead? With a right setup, private keys never leave it.−inetknght7yHardware tokens are pretty alright until you need to use GPG-agent to enable their use.−bifrost7yHardware tokens are great but most people don't know how to use them, so they don't.−scurvy7ySmart cards? They were designed for this.−bifrost7yEver seen anyone working in a Coffee shop using one? Me neither.Good security technology exists, the problem is that people don't want to use it because its easier to ignore it.−andrewshadura7yI have, and I have myself used one until it was stolen from me with a bag it was in.
Comments
How about using hardware tokens instead? With a right setup, private keys never leave it.
Hardware tokens are pretty alright until you need to use GPG-agent to enable their use.
Hardware tokens are great but most people don't know how to use them, so they don't.
Smart cards? They were designed for this.
Ever seen anyone working in a Coffee shop using one? Me neither.
Good security technology exists, the problem is that people don't want to use it because its easier to ignore it.
I have, and I have myself used one until it was stolen from me with a bag it was in.