Gigs :verified: · @beltragigs
29 followers · 41 posts · Server swiss.social

Heute von unserem IAM Chef zwei Sticks bekommen. Hab gleich mal mein iPhone mit abgesichert. Nur Windows 11 tut noch bucklig. meint, der Key gehöre nicht zur Familie, obwohl die PIN korrekt ist. Hmmm?

#Yubikey #fido2 #hello

Last updated 2 years ago

David Zaslavsky · @diazona
300 followers · 5167 posts · Server techhub.social

@PlaneSailingGames @FOSSingularity I use a to authenticate to , and I haven't heard anything about them taking that away. Actually if anything, my experience has made it seem like they're trying to push for greater adoption of Yubikeys and compatible devices.

#Yubikey #github

Last updated 2 years ago

James Bartlett :terminal: · @JamesDBartlett3
405 followers · 1380 posts · Server techhub.social

@TimWardCam
Well sure, if you're not using , but for your sake, I really hope that's not the case.

I'll tell you right now that I use @bitwarden to manage my passwords, but even if you somehow guessed the email address and password I use to unlock my vault, you still wouldn't be able to access my stuff, because you'd also need to steal my physical or my literal . If an attacker can gain physical access to my home and/or , I have much bigger problems to worry about than my online accounts.

@bitals @Nifflas

#mfa #BitWarden #Yubikey #fingerprint #biometrics

Last updated 2 years ago

xuf :geraffel: · @xuf
91 followers · 539 posts · Server geraffel.social

A research found a way to recover the password from memory dumps, This affects all versions before 2.54, which has not been released.

The article suggests to use to store the password because this keeps the password out of the system memory.

I'm quite sure this is wrong. You can even see the password entered by the . I this case the yubikey is acting like a keyboard and typing a (long random) password for you.

malwarebytes.com/blog/news/202

#keepass #yubikeys #Yubikey #dfir

Last updated 2 years ago

Deekshith Allamaneni · @dsoft
209 followers · 164 posts · Server techhub.social

🛡️ How do you manage SSH authentication?
• I hear SSH keys are good but I am concerned about saving plain keys on disk as many apps have access to it. So I only use it where automated SSH is required.
• SSH certs seem to be better but that requires setting up a separate server instance to work. My workplace uses X.509 SSH certs with Yubikey auth.
• SSH password + 2 factor auth is what I am using for some of my personal servers as of now.

If you are using SSH keys, how do you manage them?
If you use other methods, would like to know your insights.

#security #ssh #server #linux #unix #2fa #mfa #Yubikey #datasecurity

Last updated 2 years ago

Christian Mager · @cmager
7 followers · 15 posts · Server techhub.social

Did anyone else notice, that the price of 5C NFC is skyrocketing at .de since the release of 16.3?

#Yubikey #amazon #iOS

Last updated 3 years ago

Christian Mager · @cmager
6 followers · 10 posts · Server techhub.social

With 13.2 and 16.3 you can now secure your account with the new feature. To set it up you’ll need at least two FIDO compatible keys like 5Ci or 5C NFC.

👉 support.yubico.com/hc/en-us/ar
👉 support.apple.com/en-my/HT2131

#macos #ventura #iOS #iCloud #secuitykeys #Yubikey #fido #fido2 #security

Last updated 3 years ago

Ron Chmara · @ronabop
18 followers · 107 posts · Server techhub.social

@megantaylor None today, so far..

~10 Yesterday

~60 Sunday.

~80 Saturday.

~40 Friday....

(etc.)

Slowly burning through and updating a couple of decades of accounts has a lot of churn.

(Change account here, notice API call broke over there, update backup/recovery codes and schemes, check for current options, etc.)

On the plus side, finding old accounts I had forgotten about, and revisiting projects/sites I last saw in the early 00's (or even just 5 years ago) is a lot of fun!

#otp #Yubikey

Last updated 3 years ago

Marcel Waldvogel · @marcel
427 followers · 882 posts · Server waldvogel.family

@pylon Gilt ein als Tastatur? Wenn nein: Die haben eine praktische "Static Password"-Funktion…

#Yubikey

Last updated 3 years ago

David Martínez Martí · @deavid
203 followers · 352 posts · Server techhub.social

@adingbatponder I'm not sure. Maybe a or an external biometric reader. Haven't tried any. I'm happy with typing the . I feel more secure.

Because... if I don't need to type the password, that means that either the password or the cipher key must be in memory.

For the phone I ended enabling biometrics. Because it is a hassle. And I guess I can trust a non rooted android phone.

#Yubikey #password

Last updated 3 years ago

Aaron Hasty · @ahasty
2 followers · 13 posts · Server techhub.social

Anyone got any good or tips.
I currently use to store my keys. Encrypt my emails as they hit the server, if they aren't already.

I keep my notes in E2E encrypted offsite.

Data is currently stored in online

#Yubikey #gpg #joplin #owncloud #privacy #security

Last updated 3 years ago

Dis · @dis
24 followers · 68 posts · Server techhub.social

@haxd Back when I had to go to an office, Yubi/etc tokens lived on a separate "city" keychain with the door fob, bike rental fob, etc. (Hard to forget when going to the restroom, etc.)

Once I stopped that foolishness (pre-C) I printed a couple of desk organizers. My sits in a USB recess on the top of one, and the live in a USB-C organizer next to it. (Both also hold some lasers, to fend off the regular attacks.)

#Yubikey #Solokeys #cat

Last updated 3 years ago

Marcel Waldvogel 🪝 · @marcel
299 followers · 581 posts · Server waldvogel.family

@sdueckert + sind toll, aber es fehlt noch ein bisschen Feinschliff auf der Anwendungsseite.

#Yubikey #2fa

Last updated 3 years ago