You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Hi, Whonix dev here. I was wondering about your comment on Canokey which we are interested in for the purpose of adding a secure virtual smartcard feature for our hypervisor based distro.
Can you please clarify the comment you made when introducing the patchset series for QEMU:
"One note though, using CanoKey QEMU as a daily secure key is not recommended as the secret key in the emulated key is not protected by hardware."
Do you mean there is no security provided by the virtual implementation at all against hostile guest actions? Or are you saying it is less secure than a trusted physical hardware implementation in theory?
Our goal is to have something with the security properties of a similar feature called "Split GPG" provided by QubesOS [1]. I would appreciate if you give this page a quick look and let me know if canokey for QEMU provides the same security guarantees by design.
Hi, Whonix dev here. I was wondering about your comment on Canokey which we are interested in for the purpose of adding a secure virtual smartcard feature for our hypervisor based distro.
Can you please clarify the comment you made when introducing the patchset series for QEMU:
https://mail.gnu.org/archive/html/qemu-devel/2022-05/msg03913.html
Do you mean there is no security provided by the virtual implementation at all against hostile guest actions? Or are you saying it is less secure than a trusted physical hardware implementation in theory?
Our goal is to have something with the security properties of a similar feature called "Split GPG" provided by QubesOS [1]. I would appreciate if you give this page a quick look and let me know if canokey for QEMU provides the same security guarantees by design.
[1] https://www.qubes-os.org/doc/split-gpg/
The text was updated successfully, but these errors were encountered: