Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Although RSA were absolutely at fault it seems like a design failure that the seeds cannot be revoked. Give the keys 4 possible seeds and put 3 of them in a safe. Security is about having defence in depth.


How do you update the tokens though? They need to be simple, no hooking into the internet.


They could maybe have a single button that allows you to switch to a backup seed with some elaborate sequence of presses.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: