hko, (edited ) to rust
@hko@fosstodon.org avatar

Meet oct-git, a new signing and verification tool for use with the distributed version control system:

https://crates.io/crates/openpgp-card-tool-git 🦀

oct-git focuses exclusively on ergonomic use with OpenPGP card-based signing keys

It is designed to be easy to set up, standalone (no long running processes), and entirely hands-off to use (no repeated PIN entry required, by default). It comes with desktop notifications for touch confirmation (if required)

dvzrv,
@dvzrv@chaos.social avatar
rince, to random
@rince@chaos.social avatar

Ich überlege gerade ernsthaft, für meine 3 -Keys (potentiell mehr) ein von zu besorgen... wie gut ist das unter GnuPG nutzbar? Wie sind Eure Erfahrungen?

agx, to linuxphones

Laptop died yesterday but thanks to the , the Baseus Dock, an HDMI Screen, a USB keyboard and 's docked mode I have access to most of the things via my phone.

helps a lot as that means I have my ssh keys available by just plugging it in.

Took me about 15min to notice that I didn't even plug a mouse in.

stafwag, to debian
@stafwag@mastodon.social avatar

Use a GPG smartcard with Thunderbird. Part 1: setup GnuPG

https://stafwag.github.io/blog/blog/2024/04/21/use-a-gpg-smartcard-with-thunderbird-part_1-setup-gpg/

I moved to a Thinkpad w541 with coreboot so I needed to set up my email encryption on Thunderbird again.

It took me more time to reconfigure it again - as usual - so I decided to take notes this time and create a blog post about it. As this might be useful for somebody else … or me in the future :-)

#debian #email #gpg #gnupg #linux #pgp #security #thunderbird

#stafwag @stafwag

stafwag,
@stafwag@mastodon.social avatar

@adamsdesk For the fsf europe fellowship card I don't know. I got my card 8 year ago from floss-shop.de. (I live in Europe/Belgium BTW ) You can check with them if they ship to Canada.

But the setup should work with any GPG compatible smartcard. I'm also looking at Not sure if nitrokey is available on your side of the ocean 🙂

is also a option:
https://stafwag.github.io/blog/blog/2015/06/16/using-yubikey-neo-as-gpg-smartcard-for-ssh-authentication/

But I lean more to nitrokey as I have the impression that they're more active in the opensource community

gnulinux, to linux German
@gnulinux@social.anoxinon.de avatar

Zum Wochenende: Race Conditions

Wir hören auf euer Feedback. Wir reagieren auf die Community. Wir ändern die Regeln des Frühlingswettbewerbs.

https://gnulinux.ch/zum-wochenende-race-conditions

gnulinux, to community German
@gnulinux@social.anoxinon.de avatar

Zum Wochende: Frühlingswettbewerb 2024

Der Frühlingswettbewerb 2024 startet auf GNU/Linux.ch und es gibt ein tolles NitroTablet von Nitrokey zu gewinnen.

https://gnulinux.ch/zum-wochenende-fruehlingswettbewerb-2024

hko, to rust
@hko@fosstodon.org avatar

I just released https://crates.io/crates/openpgp-card-ssh-agent version 0.2.1, a new agent for card users.

This release should fix build issues (the previous version didn't build on mac).

However, we're still exploring how secret storage works on non-Linux platforms. Expect a bumpy ride if you try it.
(If you do delve into debugging on mac or windows, we'd love to hear from you!)

hko, to rust
@hko@fosstodon.org avatar

The oct tool for inspecting, configuring and using OpenPGP card devices (https://crates.io/crates/openpgp-card-tools) is on "This Week in Rust":

https://this-week-in-rust.org/blog/2024/02/21/this-week-in-rust-535/#projecttooling-updates

Yay! 🎉 Thanks again, @dvzrv 😀

nitrokey, to Cybersecurity
@nitrokey@nitrokey.com avatar

❤️ Happy Valentine's Day from your Nitrokey team! We even have a present for you! ❤️

📣 Nitrokey is giving you the privacy screen protetor and the protective case for your NitroPhone 3a in our Valentine's Bundle! Let us give you a present and start your safe smartphone use without any worries. 😍

🎉 👉 Get your Valentine's Bundle now:
https://shop.nitrokey.com/shop/valentins-bundle-nitrophone-3a-mit-kostenloser-blickschutzfolie-und-schutzhulle-636#attr=1120

bortzmeyer, to random French
@bortzmeyer@mastodon.gougere.fr avatar


Je viens de me lancer dans l'utilisation d'une clé de sécurité (une ) pour les protocoles d'authentification et . Regardons cela. https://www.bortzmeyer.org/fido2-webauthn.html

kuketzblog, to android German
@kuketzblog@social.tchncs.de avatar

Sobald Passkeys offiziell für KeePassXC (Desktop) und/oder KeePassDX (Android) verfügbar ist - nicht als Beta, sondern als Stable - wird es einen Beitrag dazu geben. 🔒

freemind,

@kuketzblog gibt es eine aktuelle Anleitung/ Beitrag zur Nutzung mit dem oder ?

Tutanota, to privacy
@Tutanota@mastodon.social avatar

Keeping your mailbox safe & secure is our . 🥰

In light of the news that Authy is discontinuing their desktop app in August of 2024, we want to let everyone know that Tuta supports all major authenticator apps & U2F keys. 🔐

No need to worry about compatibility when making the jump to a new authenticator app.🤹

👉 https://tuta.com/blog/posts/2fa-tutanota-supports-two-factor-authentication

dexternemrod,
@dexternemrod@troet.cafe avatar

@Tutanota

My @nitrokey works like a charm as well!

governa, to random
@governa@fosstodon.org avatar
jwildeboer, to random
@jwildeboer@social.wildeboer.net avatar

A rack mounted Hardware Security Module (HSM). Built with open source. Coming from Europe. What is not to like? https://www.nitrokey.com/products/nethsm

bitwarden, to random
@bitwarden@fosstodon.org avatar

In preparation for the 2023.10.0 release, Bitwarden will be undergoing server and web maintenance tonight, Oct 31st, 2023 9:00 PM–11:00 PM EDT.

Updates will be posted on the Bitwarden Status page: https://status.bitwarden.com/

ck,

@tedzanzibar I would actually urge you to disable to auto update for the extension. Looks like @bitwarden implemented support in a way that makes it unable to login using hardware tokens like the or . If you already use those as passkeys, updating the extension will effectively lock you out of services where you need a passkey to login. Tested on , but I assume will behave the same.

stv0g, (edited ) to random German
@stv0g@chaos.social avatar

I started to work on an exhaustive comparison of USB crypto tokens here: https://l.0l.de/tokens

Contributions are very welcome :)

littlealex, to random

Yey, a milestone!

I signed 2000 emails and encrypted about half of it with my smartcard 😃​

nippon, to linux German
@nippon@social.tchncs.de avatar

Eventuell habe ich die Verwendung von oder missverstanden. Aber unter ist das nicht für die alltägliche Benutzung geeignet.
Meine Vorstellung an diese Key's: Login mittels MFA, damit ich diese Codes nicht mehr eingeben muss sowohl am und - einfach an tippen und fertig, dachte ich. Die Realität sieht anders aus.

  1. Wie kann ich in MFA via NFC nutzen?
  2. Wie kann ich den Key im nutzen? Scheinbar keine Unterstützung...
kuketzblog, to Blog German
@kuketzblog@social.tchncs.de avatar

Welches Thema interessiert euch im Bereich und besonders? Gibt es einen Wunsch für ein Tutorial? Dann nutzt die Gelegenheit und macht Vorschläge. Diese bespreche ich dann mit @rufposten und wir schauen, ob und welche Themen wir näher beleuchten. 🔎

Einsendeschluss: 17. September 23 Uhr.

sunbird,

@caos @mozilla @bmaxv @kuketzblog @rufposten ja, ist aktuell, weil immer noch nicht von unterstützt wird! Warte schon dringend darauf weil ich unbedingt verwenden möchte.
Für gibts bei selbst eine Anleitung:
https://docs.nitrokey.com/de/nitrokey3/linux/openpgp-thunderbird.html?highlight=thunderbird

publicvoit, to security
@publicvoit@graz.social avatar

- the superior Multi Factor Framework
https://media.ccc.de/v/camp2023-57174-fido2
(50min) by @cy

Great overview/intro talk about using , hardware security tokens, and .

Furthermore: why FIDO2 does have some advantages compared to passkeys when is more important than convenience. Passkeys leaks your private key to the provider.

/cc @frank @keno3003

publicvoit, to security
@publicvoit@graz.social avatar
eingfoan, to random

I started to try a with all mainstream . does this have value for you in security? is there already one?

this is just a draft

it is really hard to compare since vendors are super unstructured

please for more reach

contributors welcome

eingfoan,
blake, to random

After reading https://blog.brixit.nl/nitrokey-dissapoints-me/ and seeing NitroKey's store, I'm fully convinced the entire business of is a .

They're reselling white-label hardware keys and selling modded ThinkPads and Pixel phones at a significant markup-- the NitroKey 3 Pro is just a Pixel 7 Pro with a custom ROM and an almost $600 markup.

I'd bet the certificates in their keys, just like my Thetis key (see attached & alt text), will tell you the original manufacturer of those keys.

kravietz, to random
@kravietz@agora.echelon.pl avatar

No, smartphones with chip don’t “secretly share private information with US chip-maker”. Here’s a good analysis of the lame marketing:

The author of the article has found that the device connects to izatcloud.net and instead of doing the logical thing and opening izatcloud.net in a browser they do a whois request and then figure out it’s from Qualcomm. They also proceed to contact Qualcomm lawyers instead of following the link on this page. The webpage hosted on this domain does conveniently explain who owns the domain and what it’s purpose is and it’s associated privacy policy. But that doesn’t sound nearly as spooky. The next section makes the claim that this traffic is HTTP traffic and is not encrypted. It proceeds to not show the contents of this HTTP request because it would show that it’s not at all interesting. It does not contain any private data. It’s just downloading an GPS almanac from Qualcomm for A-GPS.

https://blog.brixit.nl/nitrokey-dissapoints-me/

  • All
  • Subscribed
  • Moderated
  • Favorites
  • megavids
  • kavyap
  • DreamBathrooms
  • thenastyranch
  • magazineikmin
  • Durango
  • InstantRegret
  • Youngstown
  • ngwrru68w68
  • slotface
  • rosin
  • cisconetworking
  • GTA5RPClips
  • ethstaker
  • JUstTest
  • mdbf
  • tester
  • osvaldo12
  • tacticalgear
  • khanakhh
  • everett
  • modclub
  • anitta
  • Leos
  • cubers
  • normalnudes
  • provamag3
  • lostlight
  • All magazines