<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=16&amp;t=313" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2009-04-20T11:26:12+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=16&amp;t=313</id>
<entry>
<author><name><![CDATA[network-marvels]]></name></author>
<updated>2009-04-20T11:26:12+01:00</updated>
<published>2009-04-20T11:26:12+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=313&amp;p=1404#p1404</id>
<link href="https://forum.yubico.com/viewtopic.php?t=313&amp;p=1404#p1404"/>
<title type="html"><![CDATA[Re: Asymetric keys]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=313&amp;p=1404#p1404"><![CDATA[
Please refer to the following forum post for more information on the use of the asymmetric AES keys:<br /><br /><!-- l --><a class="postlink-local" href="http://forum.yubico.com/viewtopic.php?f=2&amp;t=68&amp;p=120#p120">viewtopic.php?f=2&amp;t=68&amp;p=120#p120</a><!-- l --><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=280">network-marvels</a> — Mon Apr 20, 2009 11:26 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[hacho]]></name></author>
<updated>2009-04-19T21:55:06+01:00</updated>
<published>2009-04-19T21:55:06+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=313&amp;p=1403#p1403</id>
<link href="https://forum.yubico.com/viewtopic.php?t=313&amp;p=1403#p1403"/>
<title type="html"><![CDATA[Asymetric keys]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=313&amp;p=1403#p1403"><![CDATA[
Hi, from what I understand YubiKey uses symetric encryption - the YubiKey device contains the AES key which is used to encrypt the OTP information and the server that authenticates the request must have the same AES key.<br /><br />Wouldn't it be better if asymetric keys were used? In this case the YubiKey device contains it's private key and the public key of the authentication server and then the server would contain only the public key of the YubiKey device.<br /><br />Wouldn't this be more secure?<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=576">hacho</a> — Sun Apr 19, 2009 9:55 pm</p><hr />
]]></content>
</entry>
</feed>