Skip to content

Login Data should not be set to IDENTITY #529

@jbagnara

Description

@jbagnara

Set Attributes section indicates that the "login data" field must be set in order to transfer subkeys:

gpg --command-fd=0 --pinentry-mode=loopback --edit-card <<EOF
admin
login
$IDENTITY
$ADMIN_PIN
quit
EOF

Setting this to $IDENTITY which likely contains PII could enable association between the yubikey and its owner.
I suggest the codeblock populate this field with a generic like "my yubikey" or "n/a", and a warning be added to the instructions.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions