fluencelabs / fluencelabs/dev-rewards

Your proof scheme will not work with FIDO based ssh keys

Open
#109 0 comments 3 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
569
Forks
359
PR merge metrics
No merged PRs in 30d

Description

Hi,

I received one of the spam emails mentioned in other issues which led me to this repo (nice of you by the way to give back to opensource this way).

I just wanted to let you know that your scheme can not work with FIDO based ssh keys (with the type `sk-ssh-ed25519@openssh.com` ), where by design the real private key cannot leave the hardware token (you still have a private key file if you want, but that's just a handle).
So you probably want to exclude those from your result set next time (or change your proof scheme), because it's impossible to generate proofs for them (unless you can extract the secret of a the hardware token, which seems a bit ... hard :thinking: )

(FIDO hardware tokens do have encryption capabilities via `hmac-secret` but AFAIK that cannot do asymmetric encryption)

Good luck with your stuff !

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.