Time for a refresher as my old key is feeling (and looking) old. Only question is, which will be the daily and which will be the backup. #YubiKey5
@schnatterer We're securing SSH via OpenPGP at work, but there are also options to do it with PIV/PKCS#11 or FIDO2
https://developers.yubico.com/PIV/Guides/SSH_with_PIV_and_PKCS11.html
https://developers.yubico.com/SSH/Securing_SSH_with_FIDO2.html
Don't know what the best way is yet, need to read more about it...
The Yubikey 5-series TOTP-Authenticator can only store a maximum of 32 Codes, which is not nearly enough for the average sec-conscious user. They claim that this will increase your security, as you will no longer require an App on your Device. This is misleading, as most FIDO2/FIDO-U2F providers require TOTP to remain active, or their Apps don't yet support FIDO. Don't waste your money - for pure FIDO2/FIDO-U2F needs, you can buy the older version. #Yubikey #FIDO2 #FIDO #WebAuthn #Yubikey5
#yubikey #fido2 #fido #webauthn #yubikey5
I may have had to physically intercept the #royalmail #postman but my new #yubikeys have finally arrived! Now the dilemma - do I go with #ed25519 keys supported by my #yubikey5 or stick with #rsa as supported by my other three #yubikey4 keys? #privacy #security #ssh #pgp
#royalmail #postman #yubikeys #ed25519 #yubikey5 #rsa #yubikey4 #privacy #security #ssh #pgp
People should be aware that #fido2 #passwordless tokens like #yubikey5 increase the number of actors that have access to their account (hackers and government agencies put aside):
• when using a password, an account can be accessed only by its user and by the service provider;
• when using a FIDO2 passwordless token, an account can be accessed by its user, by the service provider, and by the token manufacturer since this latter is in charge to generate the authenticating secret.
#fido2 #passwordless #yubikey5
Yay, #yubikey5 commandée !
Ça pique un peu niveau prix mais on verra le potentiel de fun de cette petite chose 😎