Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

As others mention, there is no point to using the Secure Enclave if you have your key stored on disk or in your backup. It’s like putting impressive locks on the front door, while leaving the window open.

Beyond that, you can do that just fine right now by making TWO keys. If you lose the laptop, oh well. Recover with your backup key (which is hopefully kept more securely than you describe - it can be inconvenient to access since it is only needed for recovery).

This also lets you go further in locking things down or providing you notifications, as you can distinguish server side between your usual key and the backup key.

The point of the enclave is to be noncloneable and access limited. Extracting the key for the backup would negate the benefits derived from that.





Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: