Fridley · @Fridley
231 followers · 954 posts · Server hachyderm.io

Time for a refresher as my old key is feeling (and looking) old. Only question is, which will be the daily and which will be the backup.

#yubikey5

Last updated 1 year ago

Brian Costa · @cronocx
18 followers · 100 posts · Server mastodon.social

Hmm, allows all the other sites I use with, wonder what’s going on here. Keys are definitely supported. (Yes, did work, but this is perplexing.)

#firefox #securitykeys #yubikey5 #safari #infosec #apple

Last updated 2 years ago

Rob · @rollin_rob
43 followers · 233 posts · Server social.linux.pizza

@schnatterer We're securing SSH via OpenPGP at work, but there are also options to do it with PIV/PKCS#11 or FIDO2
developers.yubico.com/PIV/Guid
developers.yubico.com/SSH/Secu
Don't know what the best way is yet, need to read more about it...

#yubikey5 #ssh #fido2 #pkcs

Last updated 2 years ago

ChiefBongo · @chiefbongo
36 followers · 632 posts · Server mastodon.social

The Yubikey 5-series TOTP-Authenticator can only store a maximum of 32 Codes, which is not nearly enough for the average sec-conscious user. They claim that this will increase your security, as you will no longer require an App on your Device. This is misleading, as most FIDO2/FIDO-U2F providers require TOTP to remain active, or their Apps don't yet support FIDO. Don't waste your money - for pure FIDO2/FIDO-U2F needs, you can buy the older version.

#yubikey #fido2 #fido #webauthn #yubikey5

Last updated 2 years ago

Matt Knight · @matt
55 followers · 136 posts · Server mastodon.knight.fyi

I may have had to physically intercept the but my new have finally arrived! Now the dilemma - do I go with keys supported by my or stick with as supported by my other three keys?

#royalmail #postman #yubikeys #ed25519 #yubikey5 #rsa #yubikey4 #privacy #security #ssh #pgp

Last updated 2 years ago

· @cdc
147 followers · 508 posts · Server mamot.fr

People should be aware that tokens like increase the number of actors that have access to their account (hackers and government agencies put aside):

• when using a password, an account can be accessed only by its user and by the service provider;

• when using a FIDO2 passwordless token, an account can be accessed by its user, by the service provider, and by the token manufacturer since this latter is in charge to generate the authenticating secret.

#fido2 #passwordless #yubikey5

Last updated 6 years ago

MathieuB · @MathieuB
28 followers · 484 posts · Server mastodon.xyz

Yay, commandée !
Ça pique un peu niveau prix mais on verra le potentiel de fun de cette petite chose 😎

#yubikey5

Last updated 6 years ago