Hacker News new | past | comments | ask | show | jobs | submit login

It's worth to add that the private key file generated by `ssh-keygen -t` is not the actual private key, but a reference (like a handle) to the private key stored on the secure device https://www.yubico.com/blog/github-now-supports-ssh-security...



I've been using this but you can't switch the security key, unfortunately. Just upgraded my security key and now I'm stuck with the old key.


Yes, the practical impossibility of recovering a private key from a security device is a feature. This implies you can't change security devices without changing public keys.


Yeah, I just didn't know how it works; didn't know it was stored there, but assumed it was just encrypted with the secret in the key, i.e. in the presence of the old and the new security key, it could be decrypted and re-encrypted with the new one.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: