You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Some optional security configurations are by default not on the most secure setting:
KDF-DO is off by default
All UIF (require button press for Sign/Dec/Aut) are off by default.
Given that these features improve the security of the user but are not very discoverable (and even if a user becomes aware of KDF-DO, it can only be set when no keys are stored on the device), should we consider setting default values for these? I'm thinking unique randomly generated salts for KDF-DO for each device and UIF to enabled for all. KDF-DO would be especially great as it prevents leaking the length of the PIN with CHANGE REFERENCE DATA
The text was updated successfully, but these errors were encountered:
robin-nitrokey
changed the title
Default values for optionnal security configurations?
Default values for optional security configurations?
Jul 28, 2022
Some optional security configurations are by default not on the most secure setting:
Given that these features improve the security of the user but are not very discoverable (and even if a user becomes aware of KDF-DO, it can only be set when no keys are stored on the device), should we consider setting default values for these? I'm thinking unique randomly generated salts for KDF-DO for each device and UIF to enabled for all. KDF-DO would be especially great as it prevents leaking the length of the PIN with
CHANGE REFERENCE DATA
The text was updated successfully, but these errors were encountered: