ihor, to linux
@ihor@fosstodon.org avatar

Have you ever wondered how work on ? What are they up to and how is involved? I don't know about you, but I was always curious how things are working under the hood.

Just found a nice introduction post on this matter. Check it out, it's great. Code examples are included.

https://kl.wtf/posts/2022/03/12/login-managers-an-introduction.html

ihor,
@ihor@fosstodon.org avatar

Btw, I think is an underrated piece of tech. It's pluggable, so you can implement whatever authentication strategy you want. Fingerprint check? Face recognition? You tell me.

But not only this. It can be used beyond login managers. There was one time when I played with alternative authentication for program. In my case, I wanted to tap on my instead of using password. It proved inconvenient, so I rolled things back, but it's fascinating how easy it was to configure this.

topher, to random

Banks need to support Yubikeys.

And TOTP.

This is stupid.

kkarhan,
@kkarhan@mstdn.social avatar

@topher or at the very least instead of shitty ...

Also @nitrokey >> for being fully !

beltragigs, to random German

Heute von unserem IAM Chef zwei Sticks bekommen. Hab gleich mal mein iPhone mit abgesichert. Nur Windows 11 tut noch bucklig. meint, der Key gehöre nicht zur Familie, obwohl die PIN korrekt ist. Hmmm?

CommanderViral, to security

Thanks @chiefgyk3d for the YubiKey and fidget toy! He's got some donated from to giveaway on Twitch streams, so check out his stream to get in on the Marbles games and win a .

janriemer, to github

deleted_by_author

  • Loading...
  • schizanon,
    @schizanon@mas.to avatar

    @laravista @janriemer I like the authenticator

    publicvoit, to security
    @publicvoit@graz.social avatar

    - the superior Multi Factor Framework
    https://media.ccc.de/v/camp2023-57174-fido2
    (50min) by @cy

    Great overview/intro talk about using , hardware security tokens, and .

    Furthermore: why FIDO2 does have some advantages compared to passkeys when is more important than convenience. Passkeys leaks your private key to the provider.

    /cc @frank @keno3003

    FOSSingularity, to random

    Ugh... I need to move all the code I care abt off of github, and safely to a new foss repository hosting site...

    Github decided that people HAVE to add phone numbers for 2FA, and I am not having that shit.

    A: I don't always have $ for service, and

    B: No fucking way I'm giving yet another company my phone number.

    diazona,
    @diazona@techhub.social avatar

    @PlaneSailingGames @FOSSingularity I use a to authenticate to , and I haven't heard anything about them taking that away. Actually if anything, my experience has made it seem like they're trying to push for greater adoption of Yubikeys and compatible devices.

    pezhore, to linux

    Does anyone have an updated guide for installing with full disk encryption - using a as part of MFA decryption?

    There are a few old articles/blogs - but some of them seem quite outdated. I found this: https://www.endpointdev.com/blog/2022/03/disk-decryption-yubikey/ for Ubuntu that looks like it would work for Arch - if I use dm-crypt?

    edit: removed non-functional markdown link

    drahardja, to random
    @drahardja@sfba.social avatar

    Anyone else lick their finger because otherwise it won’t activate their dongle?

    No? Just me?

    Yeah, it’s gross. But what ya gonna do?

    chiefgyk3d, to infosec
    @chiefgyk3d@social.chiefgyk3d.com avatar

    Just fixed my @Efani dashboard issues, support was great. So now that I have access to my dashboard some notes for

    TOTP Code generation shouldn't just be QR, you should also allow the string of text to be manually input. I had to use zbarimg to convert the QR code to text to input into my @yubico security key and vault for TOTP generation.
    You should also add FIDO/WebAuthn support. TOTP has a single seed, so if stolen they have access.

    chiefgyk3d,
    @chiefgyk3d@social.chiefgyk3d.com avatar

    @Efani Now for my least favorite part of making new accounts. Grabbing ALL of my @yubico to add my TOTP of FIDO/WebAuthn for my 2FA for security. Well at least I have plenty of backups. Ones with stickers are for work and the ones on my keychain aren't pictured as they are plugged in

    publicvoit, to security
    @publicvoit@graz.social avatar
    schenklklopfer, to macos German
    @schenklklopfer@chaos.social avatar

    Habe ein mit Geräten am Air M1 unter .

    Stecke ich meinen ein, kommt eine Meldung, ob ich das Gerät zulassen will, die ist aber sofort wieder weg, ich habe keine Zeit das Gerät zuzulassen.

    Ergo der Yubikey funktioniert nicht.

    Was kann ich da tun?

    :BoostOK:

    chiefgyk3d, to Cybersecurity
    @chiefgyk3d@social.chiefgyk3d.com avatar

    These nano’s are really small I was so afraid I would lose them I had to buy a lanyard for them even though I plan to keep one in my work computer. Thanks for the hookup @yubico

    chiefgyk3d, to infosec
    @chiefgyk3d@social.chiefgyk3d.com avatar

    One of my favorite things about working with as an affiliate and brand ambassador. Whenever I need keys for projects they oblige!

    bitwarden, to Cybersecurity
    @bitwarden@fosstodon.org avatar

    Further secure your digital life with . What is your favorite authenticator? https://bitwarden.com/blog/top-10-burning-questions-on-2fa/

    brianpierce,
    @brianpierce@med-mastodon.com avatar

    @bitwarden

    and for , for password management.

    pezhore,

    @bitwarden yubikey for me! I already have it for FIDO auth, adding the TOTP was easy enough, and I haven't hit the max limit of ~32 entries yet!

    potatomeow, to opensource
    @potatomeow@fosstodon.org avatar

    what is a alternative to ?

    Tutanota, to random
    @Tutanota@mastodon.social avatar

    For added security, turn on Screen Lock by storing your password in the Tutanota app. Then go to Settings > Login and choose your Unlock method. When Screen Lock is enabled, you’ll be required to open Tutanota similar to how you would unlock your phone – by entering your PIN, password, Touch ID, or Face ID.

    Happy encrypting. 🔒

    bazurk,
    @bazurk@social.lol avatar
    raymondcamden, to random
    @raymondcamden@mastodon.social avatar

    I'm "The app change its shortcut icon and now I can't find it anymore" years old.

    schizanon,
    @schizanon@mas.to avatar

    @brianleroux @raymondcamden cool thing about a for is that the app launches with so you I don't even keep it on my homescreen anymore.

    sgirlprivacy, to apple

    Anyone know a list of passkey enabled service that is not : https://passkeys.directory

    Also someone know a similar one but with login with Apple ?

    to3k, to android Polish
    @blog.tomaszdunia.pl avatar
    brunty, (edited ) to hardware
    @brunty@brunty.social avatar

    For those that use ( etc) do you have a at home or offsite? Do you just carry key(s) with you? I'm curious!

    This is a multiple choice poll, pick the option(s) that apply to you!

    Boost for reach? Thanks! 😊

    (I have a key I carry with me, as well as a backup in a secure place at home, and a key at a trusted friends place as an offsite backup. Yes, adding new keys can be frustrating with managing the offsite ones back and forth...)

    FediFollows, (edited ) to random

    & picks of the day:

    (All of these are FOSS and self-hostable)

    ➡️ @nextcloud - Host your own personal cloud, with lots of built-in services/apps you can install

    ➡️ @yunohost - Linux distro which lets you install self-hosting services through a graphic interface

    ➡️ @freedomboxfndn - Version of Linux designed to make self-hosting services easier

    ➡️ @homegrown - Site helping non-technical people use managed hosting to run their own online services

    1/5

    teon,

    And there is a great tool ( provider, , ) - @defguard

    stshank, to random
    @stshank@mstdn.social avatar

    Just logged into CVS and they prompted me to enroll a passkey. Super easy. 3 steps and I'm done. (For this browser, on this laptop — sync is the next hurdle.)

    Screenshot of CVS passkey authentication enrollment. Step 2 of 3
    Screenshot of CVS passkey authentication enrollment. Step 3 of 3

    nekodojo,

    @bouncing @mjgardner @stshank
    I keep seeing this “threat” of vendor lock-in and it’s usually a combination of “big companies can’t be trusted” and “they’re stealing your data”. Lots of FUD really.

    1. are free to generate and there’s nothing stopping you from generating more keys, one for each keychain you have. Most programs don’t export them but that feature is coming. Apple at least lets you send a copy to another device.

    So “you aren’t fully in control of them” is wrong because literally nobody else in the world has a copy of your key. You have the only copy and you can delete it or cancel it.

    1. If you don’t like big companies and don’t trust them to encrypt your data on the device, use 1password or other independent company’s app. If you are super paranoid about security you can go buy a .

    So “designed to tether users to one provider” is also wrong because you can generate more on any device you want to use.

    Try them out, it’s free!

    nekodojo,

    @bouncing @mjgardner @stshank
    What you said is exactly right. And it’s the same deal if you use apple’s iCloud Keychain to store your 50 passwords. It’s the same with any app that works on iPhone and not Android.

    Some people don’t really mind this type of “lock in” because they already have the phone and they don’t want to download another app. But you can also choose a third party solution like for your instead.

    I guess my point is that this is not something specific to passkeys. Apple makes a keychain that only works on iPhone. Google makes a keychain that only works on Android. 1Password works on both. also works on both. Passkeys is a feature they are all selling. Export doesn’t work today but creating multiple keys is free. It’s not some conspiracy plot to make you buy more phones. If it were they would not have signed on to the same standard. (In fact Microsoft already had a “passwordless” login feature that went nowhere)

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • slotface
  • ngwrru68w68
  • everett
  • mdbf
  • modclub
  • rosin
  • khanakhh
  • DreamBathrooms
  • thenastyranch
  • magazineikmin
  • Youngstown
  • GTA5RPClips
  • InstantRegret
  • provamag3
  • kavyap
  • ethstaker
  • osvaldo12
  • normalnudes
  • tacticalgear
  • cisconetworking
  • cubers
  • Durango
  • Leos
  • anitta
  • tester
  • megavids
  • lostlight
  • All magazines