stv0g, to random German
@stv0g@chaos.social avatar

I updated my crowd-sourced list of , , and , security tokens:

https://l.0l.de/tokens

Feel free to have a look if you are in the market for a new security token :-) Contributions and feedback are highly welcome :)

scy, to random
@scy@chaos.social avatar

TIL: The 5 supports setting a PIN for additional security – but only the FIPS models, not the normal ones, and only in FIPS Level 1; in Level 2 U2F is forbidden entirely and only FIDO2 can be used.

scy, to random
@scy@chaos.social avatar

Today I finally sat down to learn how keys support an "unlimited" number of websites on a single token, without compromising privacy, and without running out of memory on the token.

Reusing the same public/private keypair would allow websites to track tokens. So, the token generates a new keypair on each registration. But where is it stored?

With the website! The token encrypts the private key with a token-specific secret and receives it back from the website on each login request.

Tutanota, (edited ) to random
@Tutanota@mastodon.social avatar

What is your preferred method of ? 🔑📱

Tuta offers full support for & to keep your account secure! 🔒

👉 https://tuta.com/blog/posts/why-u2f-is-important

jsrailton, to SEC
@jsrailton@mastodon.social avatar

deleted_by_author

  • Loading...
  • publicvoit,
    @publicvoit@graz.social avatar

    @jsrailton Only FIDO2 and Passkeys are protecting against attacks.

    Caution: might copy your secret into the service provider's cloud for convenience and backup purposes.

    IMHO, hardware tokens are the only non plus ultra for authentication security since they protect your secrets in hardware without the possibility of "backups" to the cloud.

    nono2357, to security
    freakazoid, to android
    @freakazoid@retro.social avatar

    Is there a way to do authentication on a or device?

    lexd0g, to random
    @lexd0g@wetdry.world avatar

    holy fucking shit bitwarden finally got passkeys

    kkarhan,
    @kkarhan@mstdn.social avatar

    @ljrk @lexd0g everythin that uses API-Keys and/or User/Password logins.

    Good luck trying to implement for logging into a machine i mean physical, [ doesn't count!]...

    Like I'd rather use / / / instead and just chug a @nitrokey in to unlock a boot drive...

    ezlin, to random

    hm. Do I spend $30 (after shipping) on another security key, but this one can store 50 (as well as work as a standard ) entries.

    Compared to which is $50 (before shipping) and stores only 32 TOTP.

    It'd only be around $22, but it apparently ships from Switzerland?

    https://www.token2.net/shop/category/fido2-with-totp

    But it's still $20 less than the Yubikey that does the same thing but with less storage.

    Oh it's tempting!

    Gotta sleep on it. G'night world!

    ezlin, (edited ) to Discord

    actually did a fantastic thing for account and I am stoked!

    CHECK IT OUT!

    Hardware security key bayyybeee!

    and it doesn't require ANY other 2FA method to be used!

    Oh I am an excited little nerd.

    edit: Bonus, this does NOT require a paid account!

    rakkhi, to random

    Pretty cool attack after the one:

    https://retool.com/blog/mfa-isnt-mfa/

    Great reason to use that cannot enter the 2nd factor into a dodgy site

    https://rakkhi.substack.com/p/how-to-make-phishing-impossible

    ljrk, to random
    @ljrk@todon.eu avatar

    Just discovered https://github.com/WICG/web-smart-card/ for teaching instead of ... running pcsc-lite in / over (for ) or exposing the socket (e.g., Linux). Notably the is mentioned as one use case!

    I hope this gains similar traction as /// support in browsers, especially with the recent push for , as smart cards are very widely deployed in orgs and slimming down the stack would definitely be a win here.

    to3k, to android Polish
    @blog.tomaszdunia.pl avatar
    knurd42, to fedora

    This article shows how to use [#systemd #cryptenroll together with] either a #TPM2 chip or a #FIDO #U2F security key as an alternative factor to the passphrase when unlocking your [#Linux] #LUKS partitions.

    https://fedoramagazine.org/use-systemd-cryptenroll-with-fido-u2f-or-tpm2-to-decrypt-your-disk/

    eingfoan, to random

    I started to try a with all mainstream . does this have value for you in security? is there already one?

    this is just a draft

    it is really hard to compare since vendors are super unstructured

    please for more reach

    contributors welcome

    eingfoan,
    schizanon, to random

    My kingdom for a that can hold more than 30 codes

    eingfoan, to random

    Newbie question: what is best method for networks? I am playing around with a lab environment where I want good mfa inside but don’t want it to connect to the internet. My current point of view is: I can not place there since it „needs“ internet in many ways.. right? . My current way of thinking is i build a PKI into this network and use it with acting as a Smartcard but not or . Am I wrong ? Is there better options?

    w4tsn, to random
    @w4tsn@darmstadt.social avatar

    Schreibe momentan an einem Artikel zu FIDO2 / U2F Sicherheitsschlüsseln wie SoloKey2, YubiKey5 oder NitroKey3.

    Es wird darum gehen wie diese Keys mit standard tools eingerichtet und für Login in Linux oder OpenSSH eingesetzt werden können (am beispiel Fedora Linux). Vielleicht nehme ich auch gleich LUKS decryption mit auf, sonst kommt das hinterher

    Habt ihr ein besonderes Interesse bzw. Fragen auf die ich besonderen Wert legen soll?

    Edent, to security
    @Edent@mastodon.social avatar

    Where are the U2F Rings?

    The FIDO specification defines a form of Universal 2nd Factor (U2F) when users log in to a system. Rather than relying on one-time codes sent via SMS, or displayed on a phone screen, these are physical hardware tokens which are used to supplement passwords. When used with websites, this technology is also known as WebAuthn.

    I use a USB thumb-drive sized hardw

    https://shkspr.mobi/blog/2022/02/where-are-the-u2f-rings/

    #/etc/

    Edent,
    @Edent@mastodon.social avatar

    Update! They've sent me an NFC ring to review!

    Currently experimenting with and services.
    Let me know if there are any websites you'd like me to test it with.

    Can this replace my ?

    Edent,
    @Edent@mastodon.social avatar

    Two years later and... I now have a ring which works with .

    Full review coming next week 🙂

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • InstantRegret
  • DreamBathrooms
  • ethstaker
  • magazineikmin
  • osvaldo12
  • Durango
  • Youngstown
  • ngwrru68w68
  • slotface
  • rosin
  • mdbf
  • kavyap
  • khanakhh
  • megavids
  • tester
  • thenastyranch
  • cisconetworking
  • tacticalgear
  • cubers
  • everett
  • modclub
  • GTA5RPClips
  • anitta
  • Leos
  • provamag3
  • normalnudes
  • lostlight
  • All magazines