TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Krypt.co raises 1.2M to securely store your SSH private key on your phone

77 pointsby jlrubinabout 8 years ago

10 comments

gruezabout 8 years ago
It's 1.2M for an app that doesn't meaningfully increase security. Let's suppose this thing gets somewhat popular. Now malware will detect the presence of this app, wait until a legitimate request gets initiated, and piggy back off that. You approve the request, the malware logs into your servers/repos, does whatever evil thing it needs to do, let the original app do its thing, and you're none the wiser.
评论 #14492620 未加载
评论 #14492627 未加载
评论 #14492397 未加载
dmitrygrabout 8 years ago
Very professional code there .... <a href="https:&#x2F;&#x2F;github.com&#x2F;kryptco&#x2F;kryptonite-android&#x2F;blob&#x2F;master&#x2F;app&#x2F;src&#x2F;main&#x2F;cpp&#x2F;native-lib.cpp" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;kryptco&#x2F;kryptonite-android&#x2F;blob&#x2F;master&#x2F;ap...</a><p>Cannot wait to trust these guys with my ssh key!<p>&#x2F;s
评论 #14492390 未加载
评论 #14492667 未加载
floatbothabout 8 years ago
Never thought I&#x27;d see &quot;raises 1.2M&quot; and &quot;SSH private key&quot; in one sentence.<p>What would they even do with this money?
评论 #14493764 未加载
bhhaskinabout 8 years ago
Why on earth would I want my ssh keys on a device that is almost always connected to the internet if security is a major concern? A Yubikey (hardware based key) is by far the best solution.
评论 #14496176 未加载
victor9000about 8 years ago
Am I the only one around here who wants to keep their private keys private?
评论 #14497861 未加载
ovaoabout 8 years ago
I&#x27;ve been using Kryptonite a little bit and generally I&#x27;d say it&#x27;s been a pretty pleasant experience. While I personally haven&#x27;t spent much time weighing the pros and cons from a security perspective (and I&#x27;m not a security expert, so in all likelihood I&#x27;m not in a position to give a fair evaluation of it), from an overall user experience perspective these guys have done a really solid job.<p>If I have any gripe it&#x27;s that, when using with Git, Visual Studio Code&#x27;s Git autofetch feature winds up causing Kryptonite to issue a push notification to my phone every couple of minutes after first authorizing for three hours, with no way to granularly suppress notifications. That&#x27;s really kind of the point of Kryptonite, obviously, but it&#x27;s possible there&#x27;s a better solution for this on Kryptonite&#x27;s end that wouldn&#x27;t require any contortions from users.
jbb67about 8 years ago
How does this work if you lose or break your phone? I know several people who use 2FA apps on their phones to log onto services and whose phones broke and they couldn&#x27;t log on. While there is usually some way to recover your logon I&#x27;d argue that for most people and uses the chances of losing&#x2F;breaking&#x2F;replacing their phone and having to go through a painful recovery process outweigh the security advantages.
评论 #14497848 未加载
PokeAcerabout 8 years ago
Any Windows support? YubiKey&#x27;s advantage (Aswell as the fact that it&#x27;s designed for keystorage, and malware can now just target Android and can automatically approve it themselves) is that it works crossplatform; I can use a YubiKey (when I can afford one) with PuTTY - there seems to be no way to do this.
评论 #14493482 未加载
madamelicabout 8 years ago
This sounds like a neat idea but I have to agree with gruez that this is a disaster waiting to happen.<p>I carry my KeePassX DB on my phone and know it is slightly safer than typical cloud providers because it isn&#x27;t actively being targeted.<p>That said, I would try this out.
评论 #14492438 未加载
LinuxBenderabout 8 years ago
&quot;Securely&quot; and &quot;phone&quot; do not go in the same sentence.
评论 #14497854 未加载