Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Now I have to trust OpenPubkey, hoping it wont get hacked. No way will I add this to my servers, I will keep using the long live public key.


If you want to roll your own, here's another implementation which people already use, with their own OpenID Connect infrastructures.

You can deploy and use in a completely closed system.

https://github.com/EOSC-synergy/ssh-oidc


That's neat, I've added it to my reading list.


OpenPubkey is software and opensource. All software has vulnerabilities but we aren't a service or SaaS or anything.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: