<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=16&amp;t=190" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2008-09-29T22:22:39+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=16&amp;t=190</id>
<entry>
<author><name><![CDATA[paul]]></name></author>
<updated>2008-09-29T22:22:39+01:00</updated>
<published>2008-09-29T22:22:39+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=190&amp;p=719#p719</id>
<link href="https://forum.yubico.com/viewtopic.php?t=190&amp;p=719#p719"/>
<title type="html"><![CDATA[Re: Do you like to see Yubikey supports PKI (ECC)?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=190&amp;p=719#p719"><![CDATA[
<div class="quotetitle">geoff wrote:</div><div class="quotecontent"><br />If you make an ECC version of the current Yubikey model, but with ECC instead of a symmetric key it could be interesting.  The public key could be shipped with the key with no loss of security.  It would make offline authentication easier as there would be no need to preserve the security of the key as is the case with the AES based yubikey.  Of course, this does lead to problems with replay of keys as there would be no single point of authentication.<br /></div><br /><br />Good point. In that way, Yubikey can be applied to many more off-line use cases such as Windows login, door lock, etc.<br /><br /><div class="quotetitle">geoff wrote:</div><div class="quotecontent"><br />If you are suggesting a PKCS11 type product, I don't see how you would separate yourselves from the crowd.  There are already plenty players in the traditional PKI space and they all share problems with expensive infrastructure and complex integration.<br /></div><br /><br />No, absolutely not. The stack of middleware, drivers are just onerous and against Yubikey's mission.<br /><br />Thanks<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=55">paul</a> — Mon Sep 29, 2008 10:22 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[geoff]]></name></author>
<updated>2008-09-25T15:15:04+01:00</updated>
<published>2008-09-25T15:15:04+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=190&amp;p=715#p715</id>
<link href="https://forum.yubico.com/viewtopic.php?t=190&amp;p=715#p715"/>
<title type="html"><![CDATA[Re: Do you like to see Yubikey supports PKI (ECC)?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=190&amp;p=715#p715"><![CDATA[
If you make an ECC version of the current Yubikey model, but with ECC instead of a symmetric key it could be interesting.  The public key could be shipped with the key with no loss of security.  It would make offline authentication easier as there would be no need to preserve the security of the key as is the case with the AES based yubikey.  Of course, this does lead to problems with replay of keys as there would be no single point of authentication.<br /><br />If you are suggesting a PKCS11 type product, I don't see how you would separate yourselves from the crowd.  There are already plenty players in the traditional PKI space and they all share problems with expensive infrastructure and complex integration.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=270">geoff</a> — Thu Sep 25, 2008 3:15 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[paul]]></name></author>
<updated>2008-09-24T22:38:10+01:00</updated>
<published>2008-09-24T22:38:10+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=190&amp;p=712#p712</id>
<link href="https://forum.yubico.com/viewtopic.php?t=190&amp;p=712#p712"/>
<title type="html"><![CDATA[Do you like to see Yubikey supports PKI (ECC)?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=190&amp;p=712#p712"><![CDATA[
Some corporate types tell us Yubikey has to support PKI otherwise they won't adopt it. So we may consider adding ECC (Elliptic Curve Crypto) in future versions of Yubikey. <br /><br />That adds some more cost to Yubikey due to the memory and CPU power required. Here I'd like to solicit some feedback...<br /><br />* Do you hear people asking you for PKI when you demo Yubikey to them? <br /><br />* Is PKI on Yubikey a nice-to-have or must-have in your use case?<br /><br />Thanks for sharing your insights<br /><br /> <img src="https://forum.yubico.com/images/smilies/icon_question.gif" alt=":?:" title="Question" /><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=55">paul</a> — Wed Sep 24, 2008 10:38 pm</p><hr />
]]></content>
</entry>
</feed>