home.social

#fido — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #fido, aggregated by home.social.

  1. OpenAI ersetzt Passwörter und Recovery-Optionen für ChatGPT durch Hardware-Schlüssel und Passkeys.

    Die Advanced Account Security deaktiviert E-Mail- und SMS-Wiederherstellungen komplett. Konten mit dieser Stufe werden vom Training der KI-Modelle ausgeschlossen. Für Cybersecurity-Experten im Programm »Trusted Access for Cyber« wird die FIDO-kompatible Hardware-Bindung bis Juni 2026 Pflicht.

    #ChatGPT #OpenAI #Yubico #FIDO #AIGeneratedImage

    all-ai.de/news/news26/openai-s

  2. i don't want to be a curmudgeon, some of that attitude is warranted but you still have to produce and try some things. I am working on basic 5 page site template but also bigger efforts, addressing smb mkt not just local break/fix mkt. maybe the bootable nvme idea (hardened deb) with persistence and enc - a must for the road warrior but good for anyone who values security and privacy #fido #fips #extras #working drivers #vetted #pentoo #ventoy

  3. The Race Is on to Keep #AI #Agents From Running Wild With Your #CreditCards

    #AIagents may soon be buying your stuff for you. The #FIDO Alliance has teamed up with #Google and #Mastercard to try to ensure that #shopping in the near future isn't a complete disaster.
    #security

    wired.com/story/the-race-is-on

  4. I'm working to aggregate some common questions about #passkeys, both from non-technical and technical perspectives. These will be used in an end user facing site in the future.

    Any and all feedback is welcome.

    forms.gle/wmaydkzmUp2eKfJG7

    (also would appreciate some reposts to widen the audience)

    #passkey #webauthn #fido

  5. I am looking for some #localFirst solution for blog authoring what would publish (all or some) posts to an activityPub server like to a relay, with publishing of new versions of posts as updates.
    And fetch new posts, comments, mentions, messages, and reactions arrive to my local-first thing as a Feed or an Inbox.
    Sounds like I want "Fido with formatting and attachments" over #ActivityPub .
    The #Fido part is avoid need to be "always online", but sync that few times per day when have time for it

  6. Gibt es eigentlich Schweizer Banken, die das Login zum E-Banking mit gewöhnlichen Passkeys ermöglichen, ohne spezielle App, die nur mit Google oder Apple funktionieren?
    #E-Banking #passkey #fido #followerpower

  7. Rogers confirms customer information has been accessed in Rogers and Fido data breach

    mobilesyrup.com/2026/03/30/rog
    - - -
    Rogers confirme que de l’information des clients a été accédée dans la violation des données chez Rogers et Fido

    // Article en anglais //

    #Canada #Rogers #Fido #InfoSec #InformationSecurity #Cybersécurité

  8. I'm currently trying Emacs and I have a question about fido-mode:

    How do I enter a string which is a prefix or a different casing of a match? E.g. I want to rename FooBar.md to foobar.md. So I do M-x rename-file, press enter to select my current file FooBar.md, then in the "rename to" prompt I enter foobar.md. But this matches FooBar.md, so pressing enter results in Emacs trying to rename FooBar.md to FooBar.md.

    So what do I do? I feel like there must be a key I can press to disable this. But my Goolge Fu leads nowhere. 😅

    #Emacs #Fido

  9. Did you know that an USB #YubiKey emulates a keyboard? Did you also know that you need to enter your PIN to unlock a YubiKey #FIDO #WebAuthn credential? Guess what happens when you connect an external USB keyboard (or something that claims it is one) to an #Apple #iPhone? Yes, the iPhone will not display the internal keyboard because… you have an external one. Leaving you with no way to enter your PIN while the YubiKey is connected. (Intermittently, it does display the keyboard for some reason.)

  10. Wegen #Signal ist #passkeys in aller Munde.

    Aber das Verfahren ist wesentlich älter als die meisten vermuten

    Es kommt aus dem Jahre 2013 und nennt sich #FIDO2

    #passkeys ist eigentlich nur ein #Marketing Begriff

    #Fido steht für Fast IDentity Online

    Auf deutsch: schnelle Identität bei digitalen Verbindungen

    de.wikipedia.org/wiki/FIDO2

    #Datenschutz

  11. Shame on Apple for not allowing better multi-factor authentication than a simple text message. I do not own or use Apple devices, yet I require an Apple account, primarily for accessing their podcast service.

    They only support passkeys from Apple devices and security tools? That isn't standardization nor is it openness. Apple is a member of FIDO and they owe it to their users to do better.

    #MFA #FIDO #passkeys

  12. 1994 hatte ich angefangen zu studieren und habe meine ersten Erfahrungen mit Linux und dem Internet gemacht. Hier sieht man zwar meine ursprüngliche Frage nicht mehr, aber viel früher geht wirklich nicht: groups.google.com/g/fido.ger.l

    Davor war ich nur im Fido-Net unterwegs.

    #usenet #fido #nostalgie

  13. @linuxoid так можно и #Fido изобрести, только должно быть mobile first и с учётом современных веяний по децентрализации, p2p, анонимных и оверлейных сетей.

  14. Biometric Yubico (Yubikey Bio) keys! let's go. An upgrade from our Yubikey 5. And some slight changes on how we authenticate for stuff everywhere.

    Project underway! #cybersecurity #fido #2fa #authenticator #IT #sysadmin

  15. Last year we had a wee side project to get more #OPF #digitalpreservation tools added to #InfraFinder. You can now find #fido infrafinder.investinopen.org/s and #ViPER infrafinder.investinopen.org/s

    Big thanks to @carl on our end for putting together all the info. Great to see the results 🎉 Check out their update blog here: investinopen.org/blog/infra-fi

    Infra Finder is a tool from @investinopen designed to increase adoption of and investment in #openinfrastructure

  16. Экосистема SeedKey. Или как улучшить беспарольную аутентификацию

    Почему беспарольная аутентификация с помощью девайс ключей не так распространена? И почему сайты неохотно внедряют её у себя? В статье мы попытаемся разобраться с ответами на эти вопросы, и я расскажу о моем эксперименте исправить это.

    habr.com/ru/articles/984456/

    #webauthn #passkeys #беспарольная_аутентификация #passwordless #browser_extensions #fido #helm_chart #seedkey #ctap #sdk

  17. Экосистема SeedKey. Или как улучшить беспарольную аутентификацию

    Почему беспарольная аутентификация с помощью девайс ключей не так распространена? И почему сайты неохотно внедряют её у себя? В статье мы попытаемся разобраться с ответами на эти вопросы, и я расскажу о моем эксперименте исправить это.

    habr.com/ru/articles/984456/

    #webauthn #passkeys #беспарольная_аутентификация #passwordless #browser_extensions #fido #helm_chart #seedkey #ctap #sdk

  18. Экосистема SeedKey. Или как улучшить беспарольную аутентификацию

    Почему беспарольная аутентификация с помощью девайс ключей не так распространена? И почему сайты неохотно внедряют её у себя? В статье мы попытаемся разобраться с ответами на эти вопросы, и я расскажу о моем эксперименте исправить это.

    habr.com/ru/articles/984456/

    #webauthn #passkeys #беспарольная_аутентификация #passwordless #browser_extensions #fido #helm_chart #seedkey #ctap #sdk

  19. Экосистема SeedKey. Или как улучшить беспарольную аутентификацию

    Почему беспарольная аутентификация с помощью девайс ключей не так распространена? И почему сайты неохотно внедряют её у себя? В статье мы попытаемся разобраться с ответами на эти вопросы, и я расскажу о моем эксперименте исправить это.

    habr.com/ru/articles/984456/

    #webauthn #passkeys #беспарольная_аутентификация #passwordless #browser_extensions #fido #helm_chart #seedkey #ctap #sdk

  20. If you ever mess up a `git commit --gpg-sign`, for example, because you connected the wrong FIDO key or none at all, you can find your old commit message under `.git/COMMIT_EDITMSG` before trying to commit again.

    I'm a little embarrassed that I didn't realize this until this morning...

    #git #fido #fido2

  21. With the existence/acceptance of #PassKeys, is it still worth using physical #Fido keys (aka #YubiKeys) for online accounts?
    #poll #security 🗳️

  22. Yubico YubiKey: Hardware MFA required for boot is there a common alibaba equivalent to this yet for like 3 dollars? #fido #pro logic

  23. @thoralf

    Kann deine Einschätzung 100% verstehen. Ich habe mich für die Option Vpn only entschieden, da die Apps den letzten Stand cachen.
    Geräte mit Addin (Notebook) ist in meinem Fall immer mit über Vpn mit meinem Exit Node verbunden. Dadurch habe ich weitere Features wie Web Filter und meine heimische Firewall.

    Generell habe ich folgende Ideen:
    - Nutzung von #fido #fido2 -Stick/ #passkey
    - #cloudflare Zero Trust Tunnel mit Access-Filter

    Gib gerne ein Update wie du dich entschieden hast.

  24. Replacing my 2019 Yubico YubiKey 5 NFC and 5Ci with YubiKey 5C NFC variants. This time with a custom #YubiStyle

    The Double Rainbow variant will be my daily driver. The Red key will serve as the backup key in case the rainbow variant breaks.

    Now migrating all services from my old keys to the new keys. Lucky for me, I have documented all uses of my old keys.

    #security #yubikey #otp #openpgp #fido

  25. Does somebody know *why* CTAP2.x ("FIDO2") tokens do not authenticate the key exchange to protect the transmitted PIN from the client device to the authenticor?

    Background: When you enter your PIN for a FIDO2 authenticator (e.g. Yubikey), the PIN is encrypted, and only a truncated SHA-256 hash is transmitted. The encryption key is chosen by unauthenticated ephermal ECDH key exchange. As the PINs usually have low entropy, they can be brute forced by an attacker who performs an active MITM attack.

    Some smart cards (e.g. the German eID or other Biometric Passports) use PACE nowadays to protect such a key exchange with a PIN or another low-entropy secret (such as the document number) - other password authenticated key exchanges (PAKEs) would certainly be possible as well.

    Are active MITM attacks considered to be negligible for the common transports (USB, NFC, Bluetooth) of Webauth? Or are there other reasons why a PAKE is not used?

    #ctap #fido #cryptography

  26. Does somebody know *why* CTAP2.x ("FIDO2") tokens do not authenticate the key exchange to protect the transmitted PIN from the client device to the authenticor?

    Background: When you enter your PIN for a FIDO2 authenticator (e.g. Yubikey), the PIN is encrypted, and only a truncated SHA-256 hash is transmitted. The encryption key is chosen by unauthenticated ephermal ECDH key exchange. As the PINs usually have low entropy, they can be brute forced by an attacker who performs an active MITM attack.

    Some smart cards (e.g. the German eID or other Biometric Passports) use PACE nowadays to protect such a key exchange with a PIN or another low-entropy secret (such as the document number) - other password authenticated key exchanges (PAKEs) would certainly be possible as well.

    Are active MITM attacks considered to be negligible for the common transports (USB, NFC, Bluetooth) of Webauth? Or are there other reasons why a PAKE is not used?

    #ctap #fido #cryptography

  27. Does somebody know *why* CTAP2.x ("FIDO2") tokens do not authenticate the key exchange to protect the transmitted PIN from the client device to the authenticor?

    Background: When you enter your PIN for a FIDO2 authenticator (e.g. Yubikey), the PIN is encrypted, and only a truncated SHA-256 hash is transmitted. The encryption key is chosen by unauthenticated ephermal ECDH key exchange. As the PINs usually have low entropy, they can be brute forced by an attacker who performs an active MITM attack.

    Some smart cards (e.g. the German eID or other Biometric Passports) use PACE nowadays to protect such a key exchange with a PIN or another low-entropy secret (such as the document number) - other password authenticated key exchanges (PAKEs) would certainly be possible as well.

    Are active MITM attacks considered to be negligible for the common transports (USB, NFC, Bluetooth) of Webauth? Or are there other reasons why a PAKE is not used?

    #ctap #fido #cryptography

  28. @breadsmasher
    Great question! "Need" probably isn't the right word. "Strongly desire" or "greatly prefer" would more accurate.

    The reason is that I have lots of different devices with different port types. Some of my newer devices only have USB-C ports, while my older devices only have USB-A ports, and I'd really like to have just "one key to rule them all," so to speak.

    I know that I could buy a little USB-A/C adapter dongle and keep that on the same keychain with the MFA key, but that introduces a degree of fragility that I'd prefer to avoid if possible.

    That being said, if I found a hardware MFA key with all of the features I listed except for USB-C, then I'd happily accept the dongle compromise, because most of my devices (even the old ones) support Bluetooth, so I'd still have that as a backup option in case the dongle fails.

    #MFA #2FA #fido #fido2 #fido3 #NFC #USB #USBc #USBa #dongle #Biometric #Fingerprint #YubiCo #YubiKey #Bluetooth #CyberSecurity #InfoSec

  29. My current hardware MFA key is no longer receiving security patches, so I'm in the market for a new one.

    Here's a list of features I'd like my new hardware MFA key to have, in order of priority:
    1. USB-A
    2. NFC
    3. USB-C
    4. Biometric
    5. Bluetooth

    My current MFA key has features 1-3 and 5. Is there a Holy Grail MFA key somewhere out there with all 5 features?

    I'm already pretty familiar with YubiCo's product lineup, and while I love their security rating and build quality, none of them have more than 2 of the features listed above, so that kinda bums me out.

    Anyway, let's hear your hardware MFA key recommendations!

    #MFA #2FA #fido #fido2 #fido3 #NFC #USB #USBc #USBa #Biometric #Fingerprint #YubiCo #YubiKey #Bluetooth #CyberSecurity #InfoSec

  30. Linux-Tablet StarLite als Unterrichtsgerät

    StarLab vertreibt ein elegantes Linux-Tablet mit Stiftunterstützung, welches ich für den Unterricht verwenden möchte. Ich teile meine ersten Erfahrungen und Tipps.

    #Tablet #Fido #Luks #touch #Stift #Linux

    gnulinux.ch/linux-tablet-starl

  31. I'm looking for a good overview/comparison of different #MFA/#2FA or #PasswordLess authentication protocols.

    The recent #Fido2 #MitM risk made me aware that I need to learn more.

    Pointers and #BoostWelcome

    #fedipower #wisdomOfTheCrowd #FollowerPower

    As the best way to get an answer on the internet, is to state something wrong, let's try this 😜

    #FIDO and FIDO2 are actually a whole set of (related?) protocols.
    FIDO includes FIDO #UAF (Universal Authentication Framework) and FIDO #U2F (Universal Second Factor).

    FIDO2 is the "successor" of FIDO and consists of two parts.
    #WebAuthn and #CTAP (Client to Authenticator Protocol). From the name I would guess that WebAuthn is for web stuff (requiring browser support) and CTAP is for IT infrastructure stuff (???)

    #Passkey is based on #Fido2
    Other related concepts or protocols are #OTP (one-time passwords), #TOTP (Time-based One-time Password) and #HOTP (“H” in HOTP stands for Hash-based Message Authentication Code (HMAC))

    Not sure how #SmartCards play into this.

    And not sure which of these methods would work for an offline authentication login into your laptop (and ideally also as key for whole disk encryption)

  32. I'm looking for a good overview/comparison of different #MFA/#2FA or #PasswordLess authentication protocols.

    The recent #Fido2 #MitM risk made me aware that I need to learn more.

    Pointers and #BoostWelcome

    #fedipower #wisdomOfTheCrowd #FollowerPower

    As the best way to get an answer on the internet, is to state something wrong, let's try this 😜

    #FIDO and FIDO2 are actually a whole set of (related?) protocols.
    FIDO includes FIDO #UAF (Universal Authentication Framework) and FIDO #U2F (Universal Second Factor).

    FIDO2 is the "successor" of FIDO and consists of two parts.
    #WebAuthn and #CTAP (Client to Authenticator Protocol). From the name I would guess that WebAuthn is for web stuff (requiring browser support) and CTAP is for IT infrastructure stuff (???)

    #Passkey is based on #Fido2
    Other related concepts or protocols are #OTP (one-time passwords), #TOTP (Time-based One-time Password) and #HOTP (“H” in HOTP stands for Hash-based Message Authentication Code (HMAC))

    Not sure how #SmartCards play into this.

    And not sure which of these methods would work for an offline authentication login into your laptop (and ideally also as key for whole disk encryption)

  33. I'm looking for a good overview/comparison of different #MFA/#2FA or #PasswordLess authentication protocols.

    The recent #Fido2 #MitM risk made me aware that I need to learn more.

    Pointers and #BoostWelcome

    #fedipower #wisdomOfTheCrowd #FollowerPower

    As the best way to get an answer on the internet, is to state something wrong, let's try this 😜

    #FIDO and FIDO2 are actually a whole set of (related?) protocols.
    FIDO includes FIDO #UAF (Universal Authentication Framework) and FIDO #U2F (Universal Second Factor).

    FIDO2 is the "successor" of FIDO and consists of two parts.
    #WebAuthn and #CTAP (Client to Authenticator Protocol). From the name I would guess that WebAuthn is for web stuff (requiring browser support) and CTAP is for IT infrastructure stuff (???)

    #Passkey is based on #Fido2
    Other related concepts or protocols are #OTP (one-time passwords), #TOTP (Time-based One-time Password) and #HOTP (“H” in HOTP stands for Hash-based Message Authentication Code (HMAC))

    Not sure how #SmartCards play into this.

    And not sure which of these methods would work for an offline authentication login into your laptop (and ideally also as key for whole disk encryption)

  34. I'm looking for a good overview/comparison of different #MFA/#2FA or #PasswordLess authentication protocols.

    The recent #Fido2 #MitM risk made me aware that I need to learn more.

    Pointers and #BoostWelcome

    #fedipower #wisdomOfTheCrowd #FollowerPower

    As the best way to get an answer on the internet, is to state something wrong, let's try this 😜

    #FIDO and FIDO2 are actually a whole set of (related?) protocols.
    FIDO includes FIDO #UAF (Universal Authentication Framework) and FIDO #U2F (Universal Second Factor).

    FIDO2 is the "successor" of FIDO and consists of two parts.
    #WebAuthn and #CTAP (Client to Authenticator Protocol). From the name I would guess that WebAuthn is for web stuff (requiring browser support) and CTAP is for IT infrastructure stuff (???)

    #Passkey is based on #Fido2
    Other related concepts or protocols are #OTP (one-time passwords), #TOTP (Time-based One-time Password) and #HOTP (“H” in HOTP stands for Hash-based Message Authentication Code (HMAC))

    Not sure how #SmartCards play into this.

    And not sure which of these methods would work for an offline authentication login into your laptop (and ideally also as key for whole disk encryption)

  35. I'm looking for a good overview/comparison of different #MFA/#2FA or #PasswordLess authentication protocols.

    The recent #Fido2 #MitM risk made me aware that I need to learn more.

    Pointers and #BoostWelcome

    #fedipower #wisdomOfTheCrowd #FollowerPower

    As the best way to get an answer on the internet, is to state something wrong, let's try this 😜

    #FIDO and FIDO2 are actually a whole set of (related?) protocols.
    FIDO includes FIDO #UAF (Universal Authentication Framework) and FIDO #U2F (Universal Second Factor).

    FIDO2 is the "successor" of FIDO and consists of two parts.
    #WebAuthn and #CTAP (Client to Authenticator Protocol). From the name I would guess that WebAuthn is for web stuff (requiring browser support) and CTAP is for IT infrastructure stuff (???)

    #Passkey is based on #Fido2
    Other related concepts or protocols are #OTP (one-time passwords), #TOTP (Time-based One-time Password) and #HOTP (“H” in HOTP stands for Hash-based Message Authentication Code (HMAC))

    Not sure how #SmartCards play into this.

    And not sure which of these methods would work for an offline authentication login into your laptop (and ideally also as key for whole disk encryption)

  36. Does anyone know of a bank that lets you use a Fido2 security key to authenticate?

    My bank only allows SMS based 2FA, so my fiat can all be stolen by any employee of my phone company at any time.

    #2fa #security #fido2 #securityKey #yubikey #passkey #bank #fido #webauthn #auth #authentication

  37. For decades, users have authenticated on systems with usernames and passwords. This method of authentication has not changed since the beginning of the Internet. As the Internet became a more hostile place and threats emerged, ...

    blog.tinned-software.net/secur

    #security #securitykey #securitykeys #fido #fido2 #totp #passkey

  38. proton.me/blog/universal-2nd-f

    Proton has a nice beginners guide to Universal 2 Factor authentication, what it is, and why you should use it. in addition to the basics it covers some concepts such as FIDO, FIDO2 and how to use them.

    #FIDO #FIDOU2F #FIDO2 #SecurityKey #Passwordless

  39. @rmondello @urschrei

    that is a differentiation many people do not recognize until now. #fido #explain #passkey #securityKey

    Thy for pointing out that clear.

    Nevertheless… 1 question. Is there a reason why many vendors set security keys ON TOP of Uname / password?
    To me it has not so much value making it more complex?
    Or do I miss something there?