home.social

#fido2 — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #fido2, aggregated by home.social.

  1. Ho provato per settimane le YubiKey 5 NFC e 5C NFC, ecco com’è andata

    Ho provato le YubiKey 5 NFC e 5C NFC su Linux, Windows e Android: autenticazione FIDO2, passkey, codici TOTP, firma dei commit con OpenPGP, Yubico Authenticator e i limiti pratici dell’NFC.

    yoota.it/ho-provato-per-settim

  2. Ho provato per settimane le YubiKey 5 NFC e 5C NFC, ecco com’è andata

    Ho provato le YubiKey 5 NFC e 5C NFC su Linux, Windows e Android: autenticazione FIDO2, passkey, codici TOTP, firma dei commit con OpenPGP, Yubico Authenticator e i limiti pratici dell’NFC.

    yoota.it/ho-provato-per-settim

  3. Just confirmed: my TOTP seeds live on my Token2 Bio3 key itself.
    The app is just a reader. The seed never leaves the hardware.

    That said — Proton Authenticator looks genuinely excellent.
    If I didn't have a key where the seed lives on it,
    that's where I'd put my seed.

    Gigity.

    #TOTP #2FA #Infosec #ProtonAuth #Token2 #FIDO2

  4. Just confirmed: my TOTP seeds live on my Token2 Bio3 key itself.
    The app is just a reader. The seed never leaves the hardware.

    That said — Proton Authenticator looks genuinely excellent.
    If I didn't have a key where the seed lives on it,
    that's where I'd put my seed.

    Gigity.

    #TOTP #2FA #Infosec #ProtonAuth #Token2 #FIDO2

  5. Just confirmed: my TOTP seeds live on my Token2 Bio3 key itself.
    The app is just a reader. The seed never leaves the hardware.

    That said — Proton Authenticator looks genuinely excellent.
    If I didn't have a key where the seed lives on it,
    that's where I'd put my seed.

    Gigity.

    #TOTP #2FA #Infosec #ProtonAuth #Token2 #FIDO2

  6. Just confirmed: my TOTP seeds live on my Token2 Bio3 key itself.
    The app is just a reader. The seed never leaves the hardware.

    That said — Proton Authenticator looks genuinely excellent.
    If I didn't have a key where the seed lives on it,
    that's where I'd put my seed.

    Gigity.

    #TOTP #2FA #Infosec #ProtonAuth #Token2 #FIDO2

  7. Just confirmed: my TOTP seeds live on my Token2 Bio3 key itself.
    The app is just a reader. The seed never leaves the hardware.

    That said — Proton Authenticator looks genuinely excellent.
    If I didn't have a key where the seed lives on it,
    that's where I'd put my seed.

    Gigity.

    #TOTP #2FA #Infosec #ProtonAuth #Token2 #FIDO2

  8. I've just published the first v1.0.0 release candidate for Passchain (formerly HW Fido2 Provider)!

    This is a big step from something that kind of work enough to be able to use security keys without the Play Services [1][2] to a more stable app.

    Among other things, it benefit from the recent improvement made for the feature on microG (it uses its lib): for example we now have cross-device login => you can theoretically login on your TV with your Yubikey now 😃

    [1] or microG
    [2] there are now other apps like Authnkey that allow it. They didn't exist when I started Passchain, the Play Service was the only way to use them on Android

    #passchain #hwFido2Provider #passkey #fido2 #yubikey #android #microg

  9. I've just published the first v1.0.0 release candidate for Passchain (formerly HW Fido2 Provider)!

    This is a big step from something that kind of work enough to be able to use security keys without the Play Services [1][2] to a more stable app.

    Among other things, it benefit from the recent improvement made for the feature on microG (it uses its lib): for example we now have cross-device login => you can theoretically login on your TV with your Yubikey now 😃

    [1] or microG
    [2] there are now other apps like Authnkey that allow it. They didn't exist when I started Passchain, the Play Service was the only way to use them on Android

    #passchain #hwFido2Provider #passkey #fido2 #yubikey #android #microg

  10. I've just published the first v1.0.0 release candidate for Passchain (formerly HW Fido2 Provider)!

    This is a big step from something that kind of work enough to be able to use security keys without the Play Services [1][2] to a more stable app.

    Among other things, it benefit from the recent improvement made for the feature on microG (it uses its lib): for example we now have cross-device login => you can theoretically login on your TV with your Yubikey now 😃

    [1] or microG
    [2] there are now other apps like Authnkey that allow it. They didn't exist when I started Passchain, the Play Service was the only way to use them on Android

    #passchain #hwFido2Provider #passkey #fido2 #yubikey #android #microg

  11. I've just published the first v1.0.0 release candidate for Passchain (formerly HW Fido2 Provider)!

    This is a big step from something that kind of work enough to be able to use security keys without the Play Services [1][2] to a more stable app.

    Among other things, it benefit from the recent improvement made for the feature on microG (it uses its lib): for example we now have cross-device login => you can theoretically login on your TV with your Yubikey now 😃

    [1] or microG
    [2] there are now other apps like Authnkey that allow it. They didn't exist when I started Passchain, the Play Service was the only way to use them on Android

    #passchain #hwFido2Provider #passkey #fido2 #yubikey #android #microg

  12. I've just published the first v1.0.0 release candidate for Passchain (formerly HW Fido2 Provider)!

    This is a big step from something that kind of work enough to be able to use security keys without the Play Services [1][2] to a more stable app.

    Among other things, it benefit from the recent improvement made for the feature on microG (it uses its lib): for example we now have cross-device login => you can theoretically login on your TV with your Yubikey now 😃

    [1] or microG
    [2] there are now other apps like Authnkey that allow it. They didn't exist when I started Passchain, the Play Service was the only way to use them on Android

    #passchain #hwFido2Provider #passkey #fido2 #yubikey #android #microg

  13. Stories and reasoning we put to our work is often not that visible. Here is my Link project, which is partly AI implemented communication system to test various transport and security measures. It's built with buildroot and all other details can be found here: codeberg.org/resiliencetheatre
    #opsec #comsec #outofband #opensource #buildroot #embedded #lvgl #prepping #preparedness #nitrokey #fido2 #satcom

  14. Stories and reasoning we put to our work is often not that visible. Here is my Link project, which is partly AI implemented communication system to test various transport and security measures. It's built with buildroot and all other details can be found here: codeberg.org/resiliencetheatre
    #opsec #comsec #outofband #opensource #buildroot #embedded #lvgl #prepping #preparedness #nitrokey #fido2 #satcom

  15. Stories and reasoning we put to our work is often not that visible. Here is my Link project, which is partly AI implemented communication system to test various transport and security measures. It's built with buildroot and all other details can be found here: codeberg.org/resiliencetheatre
    #opsec #comsec #outofband #opensource #buildroot #embedded #lvgl #prepping #preparedness #nitrokey #fido2 #satcom

  16. UK Urges Adoption of Passkeys Over Passwords

    Say goodbye to password headaches! The UK is leading the charge towards a more secure and user-friendly login experience with passkeys, which offer stronger resilience and eliminate many common cyber threats.

    osintsights.com/uk-urges-adopt

    #Fido2 #Passkeys #PasswordManagement #NationalCyberSecurityCentre #Ncsc

  17. RE: mastodon.social/@akallabeth/11

    For the poor smucks (like myself) who are stuck needing to connect to locked down Windows remote desktops for whatever reason, I've done a thing! I contributed support for passthrough that just got released with 3.25.0, so that resources gated by passkey can be accessed in the remote machine. Please enjoy responsibly

  18. «YubiKey Manager — Sicherheitslücke ermöglicht Ausführung untergeschobenen Codes:
    Yubico warnt vor einer Suchpfad-Schwachstelle im YubiKey Manager, libfido2 und python-fido2. Updates korrigieren die Fehler.»

    Eine IT-Security Meldung die wirklich sicher ist und Updates nun wirklich sofort vor dem Wochenende gemacht werden müssen.

    🔐 heise.de/news/YubiKey-Manager-

    #update #itsicherheit #itsecurity #yubikey #libfido2 #python #fido2 #passkey #login #passkeys

  19. @Cloudsincoffee

    do they work on Linux for LUKS etc. - can you use the same package yubikey-luks? I'm currently using Yubikey, but always open for change, if it is not too difficult.

    #Yubikey #Token2 #LUKS #Linux #FIDO2 #MFA

  20. Wegen #Signal ist #passkeys in aller Munde.

    Aber das Verfahren ist wesentlich älter als die meisten vermuten

    Es kommt aus dem Jahre 2013 und nennt sich #FIDO2

    #passkeys ist eigentlich nur ein #Marketing Begriff

    #Fido steht für Fast IDentity Online

    Auf deutsch: schnelle Identität bei digitalen Verbindungen

    de.wikipedia.org/wiki/FIDO2

    #Datenschutz

  21. I wonder, are there any working SSH clients on iOS that can handle ed255519_sk keys?

    (That’s the variant where you have a public and private key part however the private key links to a residential key on an external FIDO2 security token. You plug in the token or use NFC, enter the pin and confirm with a touch)

    #ssh #fido2 #token2 #iOS #ed25519

  22. If you ever mess up a `git commit --gpg-sign`, for example, because you connected the wrong FIDO key or none at all, you can find your old commit message under `.git/COMMIT_EDITMSG` before trying to commit again.

    I'm a little embarrassed that I didn't realize this until this morning...

    #git #fido #fido2

  23. I login maybe once a year on my domain registrar's website (Gandi). Something has changed in both Firefox/Chromium since last time, because neither of them accepted any of my Yubikeys anymore: it prompted for a PIN, and I don't remember setting one! (I set one on the OpenPGP application, but that PIN is not accepted for FIDO2).

    Temporarily disabling FIDO2 allowed the login to succeed as documented here: support.yubico.com/s/article/U support.yubico.com/s/article/E
    Note that this does *not* reset FIDO2 (Which IIUC would delete the FIDO U2F key too).
    In that case IIUC it uses FIDO U2F instead of FIDO2 with a PIN. Although this seems like a bug, why doesn't the browser offer me the option of using U2F when I reject providing a FIDO2 PIN? Clearly all this worked fine several years ago when I initially registered the Yubikeys.
    #FIDO2 #Yubikey #U2F

  24. #Passkeys are everywhere nowadays
    #windowshello #fido2 #androidpasskeys #token2

    I myself switch to passkeys for any supported service. Have a look here if your services are supported: passkeys.io/who-supports-passk

    Understanding why they're more secure and why they are able to be used in so many different shapes is not as easy.

    Computerphile just released a greate video about the technology and the authentic flow:
    youtube.com/watch?v=xYfiOnufBSk

  25. This week in #FDroid (TWIF) is live since yesterday:

    * #EU #DMA for you and me
    * @mimi89999 gives us a reason to activate #NFC #Passkeys #FIDO2
    * get the app phone manufacturers hate: #CircleToSearch
    * #PeerTube is ready for creators
    * #QUIK #SMS got a new appid, did you switch yet?
    + 19 new apps
    & 160 updates
    - 2 app archived

    Touch that special place: f-droid.org/2025/12/18/twif.ht

  26. This week in #FDroid (TWIF) is live since yesterday:

    * #EU #DMA for you and me
    * @mimi89999 gives us a reason to activate #NFC #Passkeys #FIDO2
    * get the app phone manufacturers hate: #CircleToSearch
    * #PeerTube is ready for creators
    * #QUIK #SMS got a new appid, did you switch yet?
    + 19 new apps
    & 160 updates
    - 2 app archived

    Touch that special place: f-droid.org/2025/12/18/twif.ht

  27. This week in #FDroid (TWIF) is live since yesterday:

    * #EU #DMA for you and me
    * @mimi89999 gives us a reason to activate #NFC #Passkeys #FIDO2
    * get the app phone manufacturers hate: #CircleToSearch
    * #PeerTube is ready for creators
    * #QUIK #SMS got a new appid, did you switch yet?
    + 19 new apps
    & 160 updates
    - 2 app archived

    Touch that special place: f-droid.org/2025/12/18/twif.ht

  28. This week in #FDroid (TWIF) is live since yesterday:

    * #EU #DMA for you and me
    * @mimi89999 gives us a reason to activate #NFC #Passkeys #FIDO2
    * get the app phone manufacturers hate: #CircleToSearch
    * #PeerTube is ready for creators
    * #QUIK #SMS got a new appid, did you switch yet?
    + 19 new apps
    & 160 updates
    - 2 app archived

    Touch that special place: f-droid.org/2025/12/18/twif.ht

  29. This week in #FDroid (TWIF) is live since yesterday:

    * #EU #DMA for you and me
    * @mimi89999 gives us a reason to activate #NFC #Passkeys #FIDO2
    * get the app phone manufacturers hate: #CircleToSearch
    * #PeerTube is ready for creators
    * #QUIK #SMS got a new appid, did you switch yet?
    + 19 new apps
    & 160 updates
    - 2 app archived

    Touch that special place: f-droid.org/2025/12/18/twif.ht

  30. @thoralf

    Kann deine Einschätzung 100% verstehen. Ich habe mich für die Option Vpn only entschieden, da die Apps den letzten Stand cachen.
    Geräte mit Addin (Notebook) ist in meinem Fall immer mit über Vpn mit meinem Exit Node verbunden. Dadurch habe ich weitere Features wie Web Filter und meine heimische Firewall.

    Generell habe ich folgende Ideen:
    - Nutzung von #fido #fido2 -Stick/ #passkey
    - #cloudflare Zero Trust Tunnel mit Access-Filter

    Gib gerne ein Update wie du dich entschieden hast.

  31. had a nice (but crowded) time at the anarchist book fair workshops today, specifically the one about not owning a phone! lots of great convos, philosophies, and modes of existence without cell phone!

    lots of interest about, and shoutouts for @cwtch, @delta, and @briar -- e2ee (group) messengers that dont require a phone number (as a replacement for @signalapp)

    lots of interest in #U2F, #FIDO2 hardware #2FA devices (as a replacement for SMS or push). i also recommend @keepassxc for keeping TOTP tokens!

    really appreciated hearing all the side conversations about @tails, @Mastodon, and other decentralized tech

    they are already planning the next one in 2026! anarchistbookfairamsterdam.org @AFA

    #anarchistbookfairamsterdam #amsterdam #anarchism #bookfair #anarchistbookfair #activism #netherlands #antifascism

  32. had a nice (but crowded) time at the anarchist book fair workshops today, specifically the one about not owning a phone! lots of great convos, philosophies, and modes of existence without cell phone!

    lots of interest about, and shoutouts for @cwtch, @delta, and @briar -- e2ee (group) messengers that dont require a phone number (as a replacement for @signalapp)

    lots of interest in #U2F, #FIDO2 hardware #2FA devices (as a replacement for SMS or push). i also recommend @keepassxc for keeping TOTP tokens!

    really appreciated hearing all the side conversations about @tails, @Mastodon, and other decentralized tech

    they are already planning the next one in 2026! anarchistbookfairamsterdam.org @AFA

    #anarchistbookfairamsterdam #amsterdam #anarchism #bookfair #anarchistbookfair #activism #netherlands #antifascism

  33. had a nice (but crowded) time at the anarchist book fair workshops today, specifically the one about not owning a phone! lots of great convos, philosophies, and modes of existence without cell phone!

    lots of interest about, and shoutouts for @cwtch, @delta, and @briar -- e2ee (group) messengers that dont require a phone number (as a replacement for @signalapp)

    lots of interest in #U2F, #FIDO2 hardware #2FA devices (as a replacement for SMS or push). i also recommend @keepassxc for keeping TOTP tokens!

    really appreciated hearing all the side conversations about @tails, @Mastodon, and other decentralized tech

    they are already planning the next one in 2026! anarchistbookfairamsterdam.org @AFA

    #anarchistbookfairamsterdam #amsterdam #anarchism #bookfair #anarchistbookfair #activism #netherlands #antifascism

  34. had a nice (but crowded) time at the anarchist book fair workshops today, specifically the one about not owning a phone! lots of great convos, philosophies, and modes of existence without cell phone!

    lots of interest about, and shoutouts for @cwtch, @delta, and @briar -- e2ee (group) messengers that dont require a phone number (as a replacement for @signalapp)

    lots of interest in #U2F, #FIDO2 hardware #2FA devices (as a replacement for SMS or push). i also recommend @keepassxc for keeping TOTP tokens!

    really appreciated hearing all the side conversations about @tails, @Mastodon, and other decentralized tech

    they are already planning the next one in 2026! anarchistbookfairamsterdam.org @AFA

    #anarchistbookfairamsterdam #amsterdam #anarchism #bookfair #anarchistbookfair #activism #netherlands #antifascism

  35. had a nice (but crowded) time at the anarchist book fair workshops today, specifically the one about not owning a phone! lots of great convos, philosophies, and modes of existence without cell phone!

    lots of interest about, and shoutouts for @cwtch, @delta, and @briar -- e2ee (group) messengers that dont require a phone number (as a replacement for @signalapp)

    lots of interest in #U2F, #FIDO2 hardware #2FA devices (as a replacement for SMS or push). i also recommend @keepassxc for keeping TOTP tokens!

    really appreciated hearing all the side conversations about @tails, @Mastodon, and other decentralized tech

    they are already planning the next one in 2026! anarchistbookfairamsterdam.org @AFA

    #anarchistbookfairamsterdam #amsterdam #anarchism #bookfair #anarchistbookfair #activism #netherlands #antifascism

  36. FIDO2-Schlüssel zum Entsperren während des Bootens

    Anleitung zum Entsperren der LUKS Boot Partition mit einem FIDO2 Stick auf einer Fedora Silverblue Installation.

    #FIDO2 #Fedora_Silverblue #LUKS2_Volumes #Tooltip #Linux

    gnulinux.ch/fido2-schlüssel-zu

  37. Anyone familiar with #FIDO2 / #Passkeys could you please #help me here?

    Accoding to Yubico docs on Passkey, the client/client device uses #CTAP2 to communicate with platform authenticators. This sounds a bit strange to me, aren't there internal APIs on the platform that are called here? Isn't CTAP2 exclusive to #roaming authenticators?

    #advice #thaks

    developers.yubico.com/Develope