Skip to content

Can we store any sensitive data in device(yubikey) #598

Answered by martelletto
raroraca asked this question in Q&A
Discussion options

You must be logged in to vote

I am not sure I understand the question; my apologies. largeBlobs is a FIDO CTAP 2.1 extension allowing the storage of discretionary data on a FIDO authenticator. The data is opaque to the authenticator and can be anything. The only FIDO authenticator supporting largeBlobs - that I am aware of - is the YubiKey Bio, which supports blobs adding up to ~1000 bytes in size. Please note that fido2-token(1) can be used to store/fetch largeBlobs.

Edit: I realize now that you were asking about the confidentiality and authenticity aspects of largeBlobs. If libfido2 APIs (or fido2-token) are used, largeBlobs will be encrypted with a AEAD algorithm (specifically, AES-256 GCM) before being stored on t…

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@raroraca
Comment options

@martelletto
Comment options

Answer selected by martelletto
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants