Security Key Management

This cluster focuses on discussions about managing cryptographic keys, particularly challenges like revoking compromised keys, handling key loss or theft, regeneration, and recovery without backups.

📉 Falling 0.4x Security
3,806
Comments
20
Years Active
5
Top Authors
#1785
Topic ID

Activity Over Time

2007
1
2008
3
2009
9
2010
19
2011
57
2012
80
2013
171
2014
154
2015
147
2016
221
2017
286
2018
259
2019
266
2020
243
2021
347
2022
430
2023
442
2024
312
2025
317
2026
44

Keywords

AFAIK IT IMHO OP HN DKIM ActivityPub OTOH key keys private key private revoke recovery compromised device password backup

Sample Comments

paulddraper Mar 12, 2016 View on HN

Why do you think they can revoke the keys?

dozzie Jul 8, 2016 View on HN

Two keys. You don't want to be involved in the mess when one of the keys gets in your opinion compromised.

lrem Mar 14, 2021 View on HN

It does not back up keys. In case of a key loss, a new one is generated and all your contacts get a warning that your key changed.

d4mi3n Oct 27, 2021 View on HN

Still an improvement. Keys can be revoked and regenerated.

ozim Jan 26, 2022 View on HN

I think idea is that you don't backup secret key material.You should add multiple keys to your logins and have a "backup" key which is separate one.Especially when you lose physical key, you want to have different one and revoke lost one asap.The same with private keys generated on a device - private key should stay on the device on which it was generated and never copied. If you need access from a different device you generate private key on another device and transfer p

daurnimator Jan 12, 2019 View on HN

why is that a problem? a well oiled practice for revocation in case of compromise sounds like a good thing to me.

klodolph Dec 27, 2021 View on HN

How do you restore access if a user's private key is lost or compromised?

snissn Nov 11, 2020 View on HN

can you explain key management? is it via the user's password? what happens if passwords are lost or changed?

sigjuice Sep 24, 2019 View on HN

What happens if you lose or damage your key? Is there some sort of backup/recovery or fallback scheme?

n42 Jun 8, 2023 View on HN

hm. I guess these are the early days for the industry where providers are figuring this stuff out. I won't be surprised to see them add that. yes, you can lose keys, even (especially) if they are digital!