Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

So your git repo and GPG key are stored on the same device? What happens when that device is stolen?


Yubikeys that can do gpg are $40 or so and have lots of other uses.

Iirc, ssh can now do file encryption with FIDO2 keys; these are $10 or so.

Definitely worth buying a pair if you are worried about security (both Trojans, where local encryption at rest can be defeated, and losing your device where it is not)


GPG keys are usually stored encrypted at rest.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: