DeVault: Announcing the Hare programming language
DeVault: Announcing the Hare programming language
Posted May 3, 2022 10:34 UTC (Tue) by ddevault (subscriber, #99589)In reply to: DeVault: Announcing the Hare programming language by nix
Parent article: DeVault: Announcing the Hare programming language
It is not automatically insecure on other systems. Like I've explained in other comments, this is one part of a system which provides defense in depth, and the lack of a kernel-provided key store does not create any vulnerabilities in your application on its own. What's more, it was never advertised as "extra-secure", in fact, it's advertised as quite the opposite, with clear documentation explaining its limitations, a disclaimer that it has not been audited, and emphasis given on the importance of good cryptography as it pertains to the life and security of your users.
Again, the YubiKey suggestion lacks an understanding of the scope of this module and of the standard library in general.
