home.social

#security-keys — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #security-keys, aggregated by home.social.

fetched live
  1. I just bought #YubiKey|s to play around with and wanted to add them to #PayPal. Turns out, they only support adding one at a time? Wth?

    Maybe time to finally ditch PayPal after all...

    #yubikey #paypal #securitykeys #mfa #cybersecurity #rant

  2. The Silent Breach and the Persistence of Unauthorized Access

    938 words, 5 minutes read time.

    Once the session token is successfully exfiltrated, the nature of the intrusion shifts from external deception to internal subversion. The attacker does not need to crack passwords or trigger further security alerts, as they are now effectively operating with the digital identity of a trusted employee. Analyzing these incidents, I see that the primary goal is often the establishment of persistence within the target environment, which is achieved through the modification of inbox rules or the creation of clandestine mailbox delegates. By silently forwarding incoming emails to an external address or creating hidden folders for sensitive correspondence, the adversary can monitor ongoing business deals, intercept financial instructions, and identify high-value targets for subsequent business email compromise attacks. This stage of the operation is characterized by extreme patience, as the threat actor avoids loud, disruptive actions in favor of a low-and-slow approach that can remain undetected for months. The tragedy is that the victim often remains entirely unaware of the breach, believing they are still securely authenticated while their environment is being methodically picked apart from the inside.

    Challenging the Failure of Traditional Defensive Postures

    When considering why these attacks continue to succeed with such alarming frequency, it becomes evident that the industry’s reliance on legacy defensive postures is a failing strategy. Many organizations still treat email security as a static barrier, implementing blacklists and rudimentary heuristic scans that are easily circumvented by adversaries who control their own infrastructure and rotating IP addresses. Furthermore, the human-centric nature of these scams renders technical controls inherently insufficient unless they are paired with a cultural shift toward skeptical verification. It is not enough to deploy an automated solution if the culture within a firm encourages speed over accuracy and ignores the red flags of irregular communication patterns. Consequently, the defense against these campaigns must evolve into a proactive, threat-hunting discipline that monitors for anomalous login locations, unexpected session durations, and unauthorized changes to account configurations. Without this layer of vigilant oversight, the technical barriers essentially act as a screen door, providing the illusion of protection while failing to stop the actual threat.

    Implementing Rigorous Verification Protocols in a High-Stakes Environment

    The path forward requires a departure from the convenience-first mindset that dominates modern digital work environments. Organizations must adopt hardware-backed authentication methods, such as FIDO2-compliant security keys, which are resistant to the proxy-based interception tactics that currently plague mobile-based push notifications and SMS codes. Additionally, the adoption of strict device posture checks ensures that an attacker cannot simply use a stolen session token from an unauthorized machine or an unrecognized geographic region. Beyond the hardware, there must be a fundamental hardening of organizational processes, such as implementing mandatory out-of-band verification for any request involving financial transfers or the sharing of sensitive credentials. It is a harsh reality that trust is the primary vulnerability in any system, and the most secure posture is one that treats every incoming request as potentially malicious until proven otherwise through independent channels. While this might introduce friction into the workflow, that friction is the necessary price of security in an age where the cost of a single successful breach is often the survival of the entity itself.

    Call to Action

    The time for passive observation has passed, as the threats currently infiltrating our inboxes are not waiting for an invitation to compromise your organization. You must decide whether to continue relying on outdated defensive protocols that offer only the illusion of safety or to begin the hard work of hardening your infrastructure against the reality of modern adversarial tactics. I urge you to conduct an immediate audit of your current authentication stack and evaluate the necessity of migrating to hardware-backed security keys, as this is the single most effective step you can take to neutralize the threat of proxy-based session hijacking. Furthermore, initiate a comprehensive review of your internal communication policies to ensure that your team is empowered to question anomalies rather than blindly following the path of least resistance. Security is not a product you purchase, but a discipline you practice, and the responsibility to bridge the gap between your existing defenses and the current threat reality rests entirely with you. Do not wait for a compromised session to force your hand, because by the time the impact of a breach is visible, the damage is already absolute.

    SUPPORTSUBSCRIBECONTACT ME

    D. Bryan King

    Sources

    Disclaimer:

    The views and opinions expressed in this post are solely those of the author. The information provided is based on personal research, experience, and understanding of the subject matter at the time of writing. Readers should consult relevant experts or authorities for specific guidance related to their unique situations.

    Related Posts

    Rate this:

    #accountTakeover #adversaryInTheMiddle #AiTM #ATO #authenticationProtocols #BEC #businessEmailCompromise #corporatePhishing #corporateSecurity #credentialHarvesting #cyberResilience #cyberThreatIntelligence #cyberWarfare #cybersecurity #cybersecurityBestPractices #dataBreachPrevention #digitalFraud #digitalIdentity #emailScams #emailSecurity #emailThreats #enterpriseSecurity #FIDO2 #hardwareSecurity #identityTheftProtection #incidentResponse #informationSecurity #infosec #maliciousInfrastructure #MFABypass #multiFactorAuthentication #networkDefense #onlineSafety #passwordless #phishingAttacks #phishingAwareness #phishingKits #phishingResistantAuthentication #riskManagement #secureAuthentication #securityAudit #securityCulture #securityHardening #securityKeys #sessionTokenTheft #socialEngineering #threatDetection #threatLandscape #zeroTrust
  3. The Silent Breach and the Persistence of Unauthorized Access

    938 words, 5 minutes read time.

    Once the session token is successfully exfiltrated, the nature of the intrusion shifts from external deception to internal subversion. The attacker does not need to crack passwords or trigger further security alerts, as they are now effectively operating with the digital identity of a trusted employee. Analyzing these incidents, I see that the primary goal is often the establishment of persistence within the target environment, which is achieved through the modification of inbox rules or the creation of clandestine mailbox delegates. By silently forwarding incoming emails to an external address or creating hidden folders for sensitive correspondence, the adversary can monitor ongoing business deals, intercept financial instructions, and identify high-value targets for subsequent business email compromise attacks. This stage of the operation is characterized by extreme patience, as the threat actor avoids loud, disruptive actions in favor of a low-and-slow approach that can remain undetected for months. The tragedy is that the victim often remains entirely unaware of the breach, believing they are still securely authenticated while their environment is being methodically picked apart from the inside.

    Challenging the Failure of Traditional Defensive Postures

    When considering why these attacks continue to succeed with such alarming frequency, it becomes evident that the industry’s reliance on legacy defensive postures is a failing strategy. Many organizations still treat email security as a static barrier, implementing blacklists and rudimentary heuristic scans that are easily circumvented by adversaries who control their own infrastructure and rotating IP addresses. Furthermore, the human-centric nature of these scams renders technical controls inherently insufficient unless they are paired with a cultural shift toward skeptical verification. It is not enough to deploy an automated solution if the culture within a firm encourages speed over accuracy and ignores the red flags of irregular communication patterns. Consequently, the defense against these campaigns must evolve into a proactive, threat-hunting discipline that monitors for anomalous login locations, unexpected session durations, and unauthorized changes to account configurations. Without this layer of vigilant oversight, the technical barriers essentially act as a screen door, providing the illusion of protection while failing to stop the actual threat.

    Implementing Rigorous Verification Protocols in a High-Stakes Environment

    The path forward requires a departure from the convenience-first mindset that dominates modern digital work environments. Organizations must adopt hardware-backed authentication methods, such as FIDO2-compliant security keys, which are resistant to the proxy-based interception tactics that currently plague mobile-based push notifications and SMS codes. Additionally, the adoption of strict device posture checks ensures that an attacker cannot simply use a stolen session token from an unauthorized machine or an unrecognized geographic region. Beyond the hardware, there must be a fundamental hardening of organizational processes, such as implementing mandatory out-of-band verification for any request involving financial transfers or the sharing of sensitive credentials. It is a harsh reality that trust is the primary vulnerability in any system, and the most secure posture is one that treats every incoming request as potentially malicious until proven otherwise through independent channels. While this might introduce friction into the workflow, that friction is the necessary price of security in an age where the cost of a single successful breach is often the survival of the entity itself.

    Call to Action

    The time for passive observation has passed, as the threats currently infiltrating our inboxes are not waiting for an invitation to compromise your organization. You must decide whether to continue relying on outdated defensive protocols that offer only the illusion of safety or to begin the hard work of hardening your infrastructure against the reality of modern adversarial tactics. I urge you to conduct an immediate audit of your current authentication stack and evaluate the necessity of migrating to hardware-backed security keys, as this is the single most effective step you can take to neutralize the threat of proxy-based session hijacking. Furthermore, initiate a comprehensive review of your internal communication policies to ensure that your team is empowered to question anomalies rather than blindly following the path of least resistance. Security is not a product you purchase, but a discipline you practice, and the responsibility to bridge the gap between your existing defenses and the current threat reality rests entirely with you. Do not wait for a compromised session to force your hand, because by the time the impact of a breach is visible, the damage is already absolute.

    SUPPORTSUBSCRIBECONTACT ME

    D. Bryan King

    Sources

    Disclaimer:

    The views and opinions expressed in this post are solely those of the author. The information provided is based on personal research, experience, and understanding of the subject matter at the time of writing. Readers should consult relevant experts or authorities for specific guidance related to their unique situations.

    Related Posts

    Rate this:

    #accountTakeover #adversaryInTheMiddle #AiTM #ATO #authenticationProtocols #BEC #businessEmailCompromise #corporatePhishing #corporateSecurity #credentialHarvesting #cyberResilience #cyberThreatIntelligence #cyberWarfare #cybersecurity #cybersecurityBestPractices #dataBreachPrevention #digitalFraud #digitalIdentity #emailScams #emailSecurity #emailThreats #enterpriseSecurity #FIDO2 #hardwareSecurity #identityTheftProtection #incidentResponse #informationSecurity #infosec #maliciousInfrastructure #MFABypass #multiFactorAuthentication #networkDefense #onlineSafety #passwordless #phishingAttacks #phishingAwareness #phishingKits #phishingResistantAuthentication #riskManagement #secureAuthentication #securityAudit #securityCulture #securityHardening #securityKeys #sessionTokenTheft #socialEngineering #threatDetection #threatLandscape #zeroTrust
  4. The Silent Breach and the Persistence of Unauthorized Access

    938 words, 5 minutes read time.

    Once the session token is successfully exfiltrated, the nature of the intrusion shifts from external deception to internal subversion. The attacker does not need to crack passwords or trigger further security alerts, as they are now effectively operating with the digital identity of a trusted employee. Analyzing these incidents, I see that the primary goal is often the establishment of persistence within the target environment, which is achieved through the modification of inbox rules or the creation of clandestine mailbox delegates. By silently forwarding incoming emails to an external address or creating hidden folders for sensitive correspondence, the adversary can monitor ongoing business deals, intercept financial instructions, and identify high-value targets for subsequent business email compromise attacks. This stage of the operation is characterized by extreme patience, as the threat actor avoids loud, disruptive actions in favor of a low-and-slow approach that can remain undetected for months. The tragedy is that the victim often remains entirely unaware of the breach, believing they are still securely authenticated while their environment is being methodically picked apart from the inside.

    Challenging the Failure of Traditional Defensive Postures

    When considering why these attacks continue to succeed with such alarming frequency, it becomes evident that the industry’s reliance on legacy defensive postures is a failing strategy. Many organizations still treat email security as a static barrier, implementing blacklists and rudimentary heuristic scans that are easily circumvented by adversaries who control their own infrastructure and rotating IP addresses. Furthermore, the human-centric nature of these scams renders technical controls inherently insufficient unless they are paired with a cultural shift toward skeptical verification. It is not enough to deploy an automated solution if the culture within a firm encourages speed over accuracy and ignores the red flags of irregular communication patterns. Consequently, the defense against these campaigns must evolve into a proactive, threat-hunting discipline that monitors for anomalous login locations, unexpected session durations, and unauthorized changes to account configurations. Without this layer of vigilant oversight, the technical barriers essentially act as a screen door, providing the illusion of protection while failing to stop the actual threat.

    Implementing Rigorous Verification Protocols in a High-Stakes Environment

    The path forward requires a departure from the convenience-first mindset that dominates modern digital work environments. Organizations must adopt hardware-backed authentication methods, such as FIDO2-compliant security keys, which are resistant to the proxy-based interception tactics that currently plague mobile-based push notifications and SMS codes. Additionally, the adoption of strict device posture checks ensures that an attacker cannot simply use a stolen session token from an unauthorized machine or an unrecognized geographic region. Beyond the hardware, there must be a fundamental hardening of organizational processes, such as implementing mandatory out-of-band verification for any request involving financial transfers or the sharing of sensitive credentials. It is a harsh reality that trust is the primary vulnerability in any system, and the most secure posture is one that treats every incoming request as potentially malicious until proven otherwise through independent channels. While this might introduce friction into the workflow, that friction is the necessary price of security in an age where the cost of a single successful breach is often the survival of the entity itself.

    Call to Action

    The time for passive observation has passed, as the threats currently infiltrating our inboxes are not waiting for an invitation to compromise your organization. You must decide whether to continue relying on outdated defensive protocols that offer only the illusion of safety or to begin the hard work of hardening your infrastructure against the reality of modern adversarial tactics. I urge you to conduct an immediate audit of your current authentication stack and evaluate the necessity of migrating to hardware-backed security keys, as this is the single most effective step you can take to neutralize the threat of proxy-based session hijacking. Furthermore, initiate a comprehensive review of your internal communication policies to ensure that your team is empowered to question anomalies rather than blindly following the path of least resistance. Security is not a product you purchase, but a discipline you practice, and the responsibility to bridge the gap between your existing defenses and the current threat reality rests entirely with you. Do not wait for a compromised session to force your hand, because by the time the impact of a breach is visible, the damage is already absolute.

    SUPPORTSUBSCRIBECONTACT ME

    D. Bryan King

    Sources

    Disclaimer:

    The views and opinions expressed in this post are solely those of the author. The information provided is based on personal research, experience, and understanding of the subject matter at the time of writing. Readers should consult relevant experts or authorities for specific guidance related to their unique situations.

    Related Posts

    Rate this:

    #accountTakeover #adversaryInTheMiddle #AiTM #ATO #authenticationProtocols #BEC #businessEmailCompromise #corporatePhishing #corporateSecurity #credentialHarvesting #cyberResilience #cyberThreatIntelligence #cyberWarfare #cybersecurity #cybersecurityBestPractices #dataBreachPrevention #digitalFraud #digitalIdentity #emailScams #emailSecurity #emailThreats #enterpriseSecurity #FIDO2 #hardwareSecurity #identityTheftProtection #incidentResponse #informationSecurity #infosec #maliciousInfrastructure #MFABypass #multiFactorAuthentication #networkDefense #onlineSafety #passwordless #phishingAttacks #phishingAwareness #phishingKits #phishingResistantAuthentication #riskManagement #secureAuthentication #securityAudit #securityCulture #securityHardening #securityKeys #sessionTokenTheft #socialEngineering #threatDetection #threatLandscape #zeroTrust
  5. The Silent Breach and the Persistence of Unauthorized Access

    938 words, 5 minutes read time.

    Once the session token is successfully exfiltrated, the nature of the intrusion shifts from external deception to internal subversion. The attacker does not need to crack passwords or trigger further security alerts, as they are now effectively operating with the digital identity of a trusted employee. Analyzing these incidents, I see that the primary goal is often the establishment of persistence within the target environment, which is achieved through the modification of inbox rules or the creation of clandestine mailbox delegates. By silently forwarding incoming emails to an external address or creating hidden folders for sensitive correspondence, the adversary can monitor ongoing business deals, intercept financial instructions, and identify high-value targets for subsequent business email compromise attacks. This stage of the operation is characterized by extreme patience, as the threat actor avoids loud, disruptive actions in favor of a low-and-slow approach that can remain undetected for months. The tragedy is that the victim often remains entirely unaware of the breach, believing they are still securely authenticated while their environment is being methodically picked apart from the inside.

    Challenging the Failure of Traditional Defensive Postures

    When considering why these attacks continue to succeed with such alarming frequency, it becomes evident that the industry’s reliance on legacy defensive postures is a failing strategy. Many organizations still treat email security as a static barrier, implementing blacklists and rudimentary heuristic scans that are easily circumvented by adversaries who control their own infrastructure and rotating IP addresses. Furthermore, the human-centric nature of these scams renders technical controls inherently insufficient unless they are paired with a cultural shift toward skeptical verification. It is not enough to deploy an automated solution if the culture within a firm encourages speed over accuracy and ignores the red flags of irregular communication patterns. Consequently, the defense against these campaigns must evolve into a proactive, threat-hunting discipline that monitors for anomalous login locations, unexpected session durations, and unauthorized changes to account configurations. Without this layer of vigilant oversight, the technical barriers essentially act as a screen door, providing the illusion of protection while failing to stop the actual threat.

    Implementing Rigorous Verification Protocols in a High-Stakes Environment

    The path forward requires a departure from the convenience-first mindset that dominates modern digital work environments. Organizations must adopt hardware-backed authentication methods, such as FIDO2-compliant security keys, which are resistant to the proxy-based interception tactics that currently plague mobile-based push notifications and SMS codes. Additionally, the adoption of strict device posture checks ensures that an attacker cannot simply use a stolen session token from an unauthorized machine or an unrecognized geographic region. Beyond the hardware, there must be a fundamental hardening of organizational processes, such as implementing mandatory out-of-band verification for any request involving financial transfers or the sharing of sensitive credentials. It is a harsh reality that trust is the primary vulnerability in any system, and the most secure posture is one that treats every incoming request as potentially malicious until proven otherwise through independent channels. While this might introduce friction into the workflow, that friction is the necessary price of security in an age where the cost of a single successful breach is often the survival of the entity itself.

    Call to Action

    The time for passive observation has passed, as the threats currently infiltrating our inboxes are not waiting for an invitation to compromise your organization. You must decide whether to continue relying on outdated defensive protocols that offer only the illusion of safety or to begin the hard work of hardening your infrastructure against the reality of modern adversarial tactics. I urge you to conduct an immediate audit of your current authentication stack and evaluate the necessity of migrating to hardware-backed security keys, as this is the single most effective step you can take to neutralize the threat of proxy-based session hijacking. Furthermore, initiate a comprehensive review of your internal communication policies to ensure that your team is empowered to question anomalies rather than blindly following the path of least resistance. Security is not a product you purchase, but a discipline you practice, and the responsibility to bridge the gap between your existing defenses and the current threat reality rests entirely with you. Do not wait for a compromised session to force your hand, because by the time the impact of a breach is visible, the damage is already absolute.

    SUPPORTSUBSCRIBECONTACT ME

    D. Bryan King

    Sources

    Disclaimer:

    The views and opinions expressed in this post are solely those of the author. The information provided is based on personal research, experience, and understanding of the subject matter at the time of writing. Readers should consult relevant experts or authorities for specific guidance related to their unique situations.

    Related Posts

    Rate this:

    #accountTakeover #adversaryInTheMiddle #AiTM #ATO #authenticationProtocols #BEC #businessEmailCompromise #corporatePhishing #corporateSecurity #credentialHarvesting #cyberResilience #cyberThreatIntelligence #cyberWarfare #cybersecurity #cybersecurityBestPractices #dataBreachPrevention #digitalFraud #digitalIdentity #emailScams #emailSecurity #emailThreats #enterpriseSecurity #FIDO2 #hardwareSecurity #identityTheftProtection #incidentResponse #informationSecurity #infosec #maliciousInfrastructure #MFABypass #multiFactorAuthentication #networkDefense #onlineSafety #passwordless #phishingAttacks #phishingAwareness #phishingKits #phishingResistantAuthentication #riskManagement #secureAuthentication #securityAudit #securityCulture #securityHardening #securityKeys #sessionTokenTheft #socialEngineering #threatDetection #threatLandscape #zeroTrust
  6. @slink One thing I didn't mention, though: I have various models (YubiKey 5 Series and YubiKey Security Key in both USB-A and USB-C). Whether a given key actually works for FIDO2 or U2F authentication depends on a lot of factors, including in particular the navigator used (Firefox desktop vs. Firefox mobile, Chromium...), the website and whether the key is used via NFC or via USB-A or USB-C. This can be very stressful if the authentication is more than experimenting for you, and if you don't have a known-good, working combination with enough redundancy.

    When I said “no problem so far”, I meant no obviously-hardware problem and no “key used to work but doesn't anymore”. However browser software support and hardware/software compatibility can't be ignored if you rely on the keys!

    #YubiKey #FIDO2 #U2F #SecurityKeys

  7. @slink One thing I didn't mention, though: I have various models (YubiKey 5 Series and YubiKey Security Key in both USB-A and USB-C). Whether a given key actually works for FIDO2 or U2F authentication depends on a lot of factors, including in particular the navigator used (Firefox desktop vs. Firefox mobile, Chromium...), the website and whether the key is used via NFC or via USB-A or USB-C. This can be very stressful if the authentication is more than experimenting for you, and if you don't have a known-good, working combination with enough redundancy.

    When I said “no problem so far”, I meant no obviously-hardware problem and no “key used to work but doesn't anymore”. However browser software support and hardware/software compatibility can't be ignored if you rely on the keys!

    #YubiKey #FIDO2 #U2F #SecurityKeys

  8. @slink One thing I didn't mention, though: I have various models (YubiKey 5 Series and YubiKey Security Key in both USB-A and USB-C). Whether a given key actually works for FIDO2 or U2F authentication depends on a lot of factors, including in particular the navigator used (Firefox desktop vs. Firefox mobile, Chromium...), the website and whether the key is used via NFC or via USB-A or USB-C. This can be very stressful if the authentication is more than experimenting for you, and if you don't have a known-good, working combination with enough redundancy.

    When I said “no problem so far”, I meant no obviously-hardware problem and no “key used to work but doesn't anymore”. However browser software support and hardware/software compatibility can't be ignored if you rely on the keys!

    #YubiKey #FIDO2 #U2F #SecurityKeys

  9. @slink One thing I didn't mention, though: I have various models (YubiKey 5 Series and YubiKey Security Key in both USB-A and USB-C). Whether a given key actually works for FIDO2 or U2F authentication depends on a lot of factors, including in particular the navigator used (Firefox desktop vs. Firefox mobile, Chromium...), the website and whether the key is used via NFC or via USB-A or USB-C. This can be very stressful if the authentication is more than experimenting for you, and if you don't have a known-good, working combination with enough redundancy.

    When I said “no problem so far”, I meant no obviously-hardware problem and no “key used to work but doesn't anymore”. However browser software support and hardware/software compatibility can't be ignored if you rely on the keys!

    #YubiKey #FIDO2 #U2F #SecurityKeys

  10. @slink One thing I didn't mention, though: I have various models (YubiKey 5 Series and YubiKey Security Key in both USB-A and USB-C). Whether a given key actually works for FIDO2 or U2F authentication depends on a lot of factors, including in particular the navigator used (Firefox desktop vs. Firefox mobile, Chromium...), the website and whether the key is used via NFC or via USB-A or USB-C. This can be very stressful if the authentication is more than experimenting for you, and if you don't have a known-good, working combination with enough redundancy.

    When I said “no problem so far”, I meant no obviously-hardware problem and no “key used to work but doesn't anymore”. However browser software support and hardware/software compatibility can't be ignored if you rely on the keys!

    #YubiKey #FIDO2 #U2F #SecurityKeys

  11. Anyone got a recommendation for a low profile USB-C opensource physical security key?

    I know about solokeys, but unlike yubikey, they don't have a short USB-C security key.

    I also saw Somu (also solokeys) which are the right form factor, but they only support USB-A.

    If not, do you know if solokey is ever gonna come out with a mini USB-C key? I really need a tiny yubikey type thing I can just forget about.

    (I have full sized keys already as backups, just in case.)

    Edit: I've added a picture of the YubiKey 5C Nano as an example of what I'm after. The idea is that the total length that sticks out from the computer is very very small, and therefore is less likely to break off.

    #yubikkey #solokey #somukey #securitykeys #FIDO2 #FIDO2SecurityKeys #FOSS

  12. Anyone got a recommendation for a low profile USB-C opensource physical security key?

    I know about solokeys, but unlike yubikey, they don't have a short USB-C security key.

    I also saw Somu (also solokeys) which are the right form factor, but they only support USB-A.

    If not, do you know if solokey is ever gonna come out with a mini USB-C key? I really need a tiny yubikey type thing I can just forget about.

    (I have full sized keys already as backups, just in case.)

    Edit: I've added a picture of the YubiKey 5C Nano as an example of what I'm after. The idea is that the total length that sticks out from the computer is very very small, and therefore is less likely to break off.

    #yubikkey #solokey #somukey #securitykeys #FIDO2 #FIDO2SecurityKeys #FOSS

  13. Anyone got a recommendation for a low profile USB-C opensource physical security key?

    I know about solokeys, but unlike yubikey, they don't have a short USB-C security key.

    I also saw Somu (also solokeys) which are the right form factor, but they only support USB-A.

    If not, do you know if solokey is ever gonna come out with a mini USB-C key? I really need a tiny yubikey type thing I can just forget about.

    (I have full sized keys already as backups, just in case.)

    Edit: I've added a picture of the YubiKey 5C Nano as an example of what I'm after. The idea is that the total length that sticks out from the computer is very very small, and therefore is less likely to break off.

    #yubikkey #solokey #somukey #securitykeys #FIDO2 #FIDO2SecurityKeys #FOSS

  14. Anyone got a recommendation for a low profile USB-C opensource physical security key?

    I know about solokeys, but unlike yubikey, they don't have a short USB-C security key.

    I also saw Somu (also solokeys) which are the right form factor, but they only support USB-A.

    If not, do you know if solokey is ever gonna come out with a mini USB-C key? I really need a tiny yubikey type thing I can just forget about.

    (I have full sized keys already as backups, just in case.)

    Edit: I've added a picture of the YubiKey 5C Nano as an example of what I'm after. The idea is that the total length that sticks out from the computer is very very small, and therefore is less likely to break off.

    #yubikkey #solokey #somukey #securitykeys #FIDO2 #FIDO2SecurityKeys #FOSS

  15. Anyone got a recommendation for a low profile USB-C opensource physical security key?

    I know about solokeys, but unlike yubikey, they don't have a short USB-C security key.

    I also saw Somu (also solokeys) which are the right form factor, but they only support USB-A.

    If not, do you know if solokey is ever gonna come out with a mini USB-C key? I really need a tiny yubikey type thing I can just forget about.

    (I have full sized keys already as backups, just in case.)

    Edit: I've added a picture of the YubiKey 5C Nano as an example of what I'm after. The idea is that the total length that sticks out from the computer is very very small, and therefore is less likely to break off.

    #yubikkey #solokey #somukey #securitykeys #FIDO2 #FIDO2SecurityKeys #FOSS

  16. Actually, you just significantly reduced my security, Gandi. You should have let the users manage this transition, or at least warn them ahead of time what was going to happen if they didn't.

    Replacing unphishable auth (old school U2F is still quite functional!) with phishable auth (email) without user consent is not acceptable.

    #Gandi #SecurityKeys #U2F

  17. Actually, you just significantly reduced my security, Gandi. You should have let the users manage this transition, or at least warn them ahead of time what was going to happen if they didn't.

    Replacing unphishable auth (old school U2F is still quite functional!) with phishable auth (email) without user consent is not acceptable.

    #Gandi #SecurityKeys #U2F

  18. Actually, you just significantly reduced my security, Gandi. You should have let the users manage this transition, or at least warn them ahead of time what was going to happen if they didn't.

    Replacing unphishable auth (old school U2F is still quite functional!) with phishable auth (email) without user consent is not acceptable.

    #Gandi #SecurityKeys #U2F

  19. Actually, you just significantly reduced my security, Gandi. You should have let the users manage this transition, or at least warn them ahead of time what was going to happen if they didn't.

    Replacing unphishable auth (old school U2F is still quite functional!) with phishable auth (email) without user consent is not acceptable.

    #Gandi #SecurityKeys #U2F

  20. Actually, you just significantly reduced my security, Gandi. You should have let the users manage this transition, or at least warn them ahead of time what was going to happen if they didn't.

    Replacing unphishable auth (old school U2F is still quite functional!) with phishable auth (email) without user consent is not acceptable.

    #Gandi #SecurityKeys #U2F

  21. Durch den #CLT2025 Talk zu Passwortlose Logins mit #PassKeys media.ccc.de/v/clt25-188-passw bin ich auf die #Token2 PIN+ #Securitykeys aufmerksam geworden token2.com/shop/category/pin-p
    Die DualPort Keys sind wohl sehr nützlich, haben 300 Resident Keys, kommen mit Hülle und kosten nur 26€.
    Zur Wasserfestigkeit finde ich leider nichts.
    Würde mich über Erfahrungsberichte freuen.
    #FIDO2

  22. Durch den #CLT2025 Talk zu Passwortlose Logins mit #PassKeys media.ccc.de/v/clt25-188-passw bin ich auf die #Token2 PIN+ #Securitykeys aufmerksam geworden token2.com/shop/category/pin-p
    Die DualPort Keys sind wohl sehr nützlich, haben 300 Resident Keys, kommen mit Hülle und kosten nur 26€.
    Zur Wasserfestigkeit finde ich leider nichts.
    Würde mich über Erfahrungsberichte freuen.
    #FIDO2

  23. Durch den #CLT2025 Talk zu Passwortlose Logins mit #PassKeys media.ccc.de/v/clt25-188-passw bin ich auf die #Token2 PIN+ #Securitykeys aufmerksam geworden token2.com/shop/category/pin-p
    Die DualPort Keys sind wohl sehr nützlich, haben 300 Resident Keys, kommen mit Hülle und kosten nur 26€.
    Zur Wasserfestigkeit finde ich leider nichts.
    Würde mich über Erfahrungsberichte freuen.
    #FIDO2

  24. Well, that's something you don't see every day - a still-panelized set of 16 security keys!

    I'm told these were part of Google's Titan / Gnubby development process. (Artemis was a daughter of Leto, who was a Titan -- get it?)

    I assume they don't have firmware on them yet, but it might be tricky to find out non-invasively.

    #SecurityKeys #Gnubby

  25. Well, that's something you don't see every day - a still-panelized set of 16 security keys!

    I'm told these were part of Google's Titan / Gnubby development process. (Artemis was a daughter of Leto, who was a Titan -- get it?)

    I assume they don't have firmware on them yet, but it might be tricky to find out non-invasively.

    #SecurityKeys #Gnubby

  26. Well, that's something you don't see every day - a still-panelized set of 16 security keys!

    I'm told these were part of Google's Titan / Gnubby development process. (Artemis was a daughter of Leto, who was a Titan -- get it?)

    I assume they don't have firmware on them yet, but it might be tricky to find out non-invasively.

    #SecurityKeys #Gnubby

  27. Well, that's something you don't see every day - a still-panelized set of 16 security keys!

    I'm told these were part of Google's Titan / Gnubby development process. (Artemis was a daughter of Leto, who was a Titan -- get it?)

    I assume they don't have firmware on them yet, but it might be tricky to find out non-invasively.

    #SecurityKeys #Gnubby

  28. Well, that's something you don't see every day - a still-panelized set of 16 security keys!

    I'm told these were part of Google's Titan / Gnubby development process. (Artemis was a daughter of Leto, who was a Titan -- get it?)

    I assume they don't have firmware on them yet, but it might be tricky to find out non-invasively.

    #SecurityKeys #Gnubby

  29. Security key that's new to me: Thetis Nano-C!

    thetis.io/products/thetis-nano

    Also news to me, I'm clearly behind: FIDO2 has levels:

    fidoalliance.org/certification

    This key is FIDO2 L1, and different applications may require different levels. Notably here, L1 is the minimum to get any certification at all, and you can't get L2 unless you have an actual secure hardware element. So with the device at this level, you get the independence of a separate physical object with a dramatically simpler software surface, but I suspect it might be easier to get secrets right off the key with physical possession.

    (Note that this is an organic post, not sponsored in any way. Happened upon it in an eBay listing. I never do solicited or compensated endorsements)

    #SecurityKeys

  30. Security key that's new to me: Thetis Nano-C!

    thetis.io/products/thetis-nano

    Also news to me, I'm clearly behind: FIDO2 has levels:

    fidoalliance.org/certification

    This key is FIDO2 L1, and different applications may require different levels. Notably here, L1 is the minimum to get any certification at all, and you can't get L2 unless you have an actual secure hardware element. So with the device at this level, you get the independence of a separate physical object with a dramatically simpler software surface, but I suspect it might be easier to get secrets right off the key with physical possession.

    (Note that this is an organic post, not sponsored in any way. Happened upon it in an eBay listing. I never do solicited or compensated endorsements)

    #SecurityKeys

  31. Security key that's new to me: Thetis Nano-C!

    thetis.io/products/thetis-nano

    Also news to me, I'm clearly behind: FIDO2 has levels:

    fidoalliance.org/certification

    This key is FIDO2 L1, and different applications may require different levels. Notably here, L1 is the minimum to get any certification at all, and you can't get L2 unless you have an actual secure hardware element. So with the device at this level, you get the independence of a separate physical object with a dramatically simpler software surface, but I suspect it might be easier to get secrets right off the key with physical possession.

    (Note that this is an organic post, not sponsored in any way. Happened upon it in an eBay listing. I never do solicited or compensated endorsements)

    #SecurityKeys

  32. Security key that's new to me: Thetis Nano-C!

    thetis.io/products/thetis-nano

    Also news to me, I'm clearly behind: FIDO2 has levels:

    fidoalliance.org/certification

    This key is FIDO2 L1, and different applications may require different levels. Notably here, L1 is the minimum to get any certification at all, and you can't get L2 unless you have an actual secure hardware element. So with the device at this level, you get the independence of a separate physical object with a dramatically simpler software surface, but I suspect it might be easier to get secrets right off the key with physical possession.

    (Note that this is an organic post, not sponsored in any way. Happened upon it in an eBay listing. I never do solicited or compensated endorsements)

    #SecurityKeys

  33. Security key that's new to me: Thetis Nano-C!

    thetis.io/products/thetis-nano

    Also news to me, I'm clearly behind: FIDO2 has levels:

    fidoalliance.org/certification

    This key is FIDO2 L1, and different applications may require different levels. Notably here, L1 is the minimum to get any certification at all, and you can't get L2 unless you have an actual secure hardware element. So with the device at this level, you get the independence of a separate physical object with a dramatically simpler software surface, but I suspect it might be easier to get secrets right off the key with physical possession.

    (Note that this is an organic post, not sponsored in any way. Happened upon it in an eBay listing. I never do solicited or compensated endorsements)

    #SecurityKeys

  34. GoDaddy makes you pick which security key you want to be prompted for by default, and only allows this key to be presented unless you follow the "try another way" workflow.

    What is the purpose / threat model of this? It seems unnecessarily high friction to me, and as far as I know is not done by any other platform.

    #SecurityKeys

  35. GoDaddy makes you pick which security key you want to be prompted for by default, and only allows this key to be presented unless you follow the "try another way" workflow.

    What is the purpose / threat model of this? It seems unnecessarily high friction to me, and as far as I know is not done by any other platform.

    #SecurityKeys

  36. GoDaddy makes you pick which security key you want to be prompted for by default, and only allows this key to be presented unless you follow the "try another way" workflow.

    What is the purpose / threat model of this? It seems unnecessarily high friction to me, and as far as I know is not done by any other platform.

    #SecurityKeys

  37. GoDaddy makes you pick which security key you want to be prompted for by default, and only allows this key to be presented unless you follow the "try another way" workflow.

    What is the purpose / threat model of this? It seems unnecessarily high friction to me, and as far as I know is not done by any other platform.

    #SecurityKeys

  38. GoDaddy makes you pick which security key you want to be prompted for by default, and only allows this key to be presented unless you follow the "try another way" workflow.

    What is the purpose / threat model of this? It seems unnecessarily high friction to me, and as far as I know is not done by any other platform.

    #SecurityKeys

  39. Since the last time I logged in fresh, Google has moved "2-step only" (non-passkey) security keys to be the first factor prompted for.

    Only after a good key is presented is the user prompted for their password.

    You are then prompted to create a passkey "instead", with a "Not now" option.

    #SecurityKeys #MFA

  40. Since the last time I logged in fresh, Google has moved "2-step only" (non-passkey) security keys to be the first factor prompted for.

    Only after a good key is presented is the user prompted for their password.

    You are then prompted to create a passkey "instead", with a "Not now" option.

    #SecurityKeys #MFA

  41. Since the last time I logged in fresh, Google has moved "2-step only" (non-passkey) security keys to be the first factor prompted for.

    Only after a good key is presented is the user prompted for their password.

    You are then prompted to create a passkey "instead", with a "Not now" option.

    #SecurityKeys #MFA

  42. Since the last time I logged in fresh, Google has moved "2-step only" (non-passkey) security keys to be the first factor prompted for.

    Only after a good key is presented is the user prompted for their password.

    You are then prompted to create a passkey "instead", with a "Not now" option.

    #SecurityKeys #MFA

  43. Since the last time I logged in fresh, Google has moved "2-step only" (non-passkey) security keys to be the first factor prompted for.

    Only after a good key is presented is the user prompted for their password.

    You are then prompted to create a passkey "instead", with a "Not now" option.

    #SecurityKeys #MFA

  44. TIL Proton dropped their maximum supported security keys (some time after mid-August 2024) from 8 to 4 keys?! (Notice the tiny "8 out of 4" label, because I had registered the maximum 8 keys)

    I suspect my current config will be stable until I need to explicitly delete a key, in which case I won't be able to add a replacement unless I delete five keys. 😡

    #MFA #SecurityKeys #FIDO2 #Proton

  45. TIL Proton dropped their maximum supported security keys (some time after mid-August 2024) from 8 to 4 keys?! (Notice the tiny "8 out of 4" label, because I had registered the maximum 8 keys)

    I suspect my current config will be stable until I need to explicitly delete a key, in which case I won't be able to add a replacement unless I delete five keys. 😡

    #MFA #SecurityKeys #FIDO2 #Proton

  46. TIL Proton dropped their maximum supported security keys (some time after mid-August 2024) from 8 to 4 keys?! (Notice the tiny "8 out of 4" label, because I had registered the maximum 8 keys)

    I suspect my current config will be stable until I need to explicitly delete a key, in which case I won't be able to add a replacement unless I delete five keys. 😡

    #MFA #SecurityKeys #FIDO2 #Proton

  47. TIL Proton dropped their maximum supported security keys (some time after mid-August 2024) from 8 to 4 keys?! (Notice the tiny "8 out of 4" label, because I had registered the maximum 8 keys)

    I suspect my current config will be stable until I need to explicitly delete a key, in which case I won't be able to add a replacement unless I delete five keys. 😡

    #MFA #SecurityKeys #FIDO2 #Proton

  48. TIL Proton dropped their maximum supported security keys (some time after mid-August 2024) from 8 to 4 keys?! (Notice the tiny "8 out of 4" label, because I had registered the maximum 8 keys)

    I suspect my current config will be stable until I need to explicitly delete a key, in which case I won't be able to add a replacement unless I delete five keys. 😡

    #MFA #SecurityKeys #FIDO2 #Proton

  49. @aleidk I replaced “mobile phone account“ with “mobile phone provider account” to be clearer about what I meant.

    For banks (in the EU), AFAIK there is a strong reason why they never even mention FIDO2: for a transaction at least, the device where validation is performed must give basic info on the transaction: seller and amount.

    Another point: the software support depends on site, browser (e.g., Firefox desktop != Firefox mobile), type of key, physical communication protocol (like USB vs. NFC). I made a lot of tests with various sites and my USB-A and USB-C keys, sometimes using NFC, other times USB. Some combinations don't work, or worked at some point and not later (or worked with Chrome but not Firefox, etc.). This can be quite stressful or even dangerous if this is for an important account and you have no backup plan (⇒ don't). And if the backup options are 1) exploitable in your threat model and 2) not very secure, this obviously reduces or nukes the advantage of using a security key in the first place.

    A typical backup option which is not insecure from my POV if well handled is a set of recovery codes, but for this you need to store them very carefully, safely... and not forget how to access them in x years! In these conditions, setting up a new account requires “some work”.

    And I say all this despite wishing FIDO2 great success, 'cause SIM swapping attacks in particular are quite scary given how much important stuff still depends on codes sent by SMS. 😐

    #FIDO2 #SecurityKeys #authentication #threatModel

  50. @aleidk I replaced “mobile phone account“ with “mobile phone provider account” to be clearer about what I meant.

    For banks (in the EU), AFAIK there is a strong reason why they never even mention FIDO2: for a transaction at least, the device where validation is performed must give basic info on the transaction: seller and amount.

    Another point: the software support depends on site, browser (e.g., Firefox desktop != Firefox mobile), type of key, physical communication protocol (like USB vs. NFC). I made a lot of tests with various sites and my USB-A and USB-C keys, sometimes using NFC, other times USB. Some combinations don't work, or worked at some point and not later (or worked with Chrome but not Firefox, etc.). This can be quite stressful or even dangerous if this is for an important account and you have no backup plan (⇒ don't). And if the backup options are 1) exploitable in your threat model and 2) not very secure, this obviously reduces or nukes the advantage of using a security key in the first place.

    A typical backup option which is not insecure from my POV if well handled is a set of recovery codes, but for this you need to store them very carefully, safely... and not forget how to access them in x years! In these conditions, setting up a new account requires “some work”.

    And I say all this despite wishing FIDO2 great success, 'cause SIM swapping attacks in particular are quite scary given how much important stuff still depends on codes sent by SMS. 😐

    #FIDO2 #SecurityKeys #authentication #threatModel

  51. @aleidk I replaced “mobile phone account“ with “mobile phone provider account” to be clearer about what I meant.

    For banks (in the EU), AFAIK there is a strong reason why they never even mention FIDO2: for a transaction at least, the device where validation is performed must give basic info on the transaction: seller and amount.

    Another point: the software support depends on site, browser (e.g., Firefox desktop != Firefox mobile), type of key, physical communication protocol (like USB vs. NFC). I made a lot of tests with various sites and my USB-A and USB-C keys, sometimes using NFC, other times USB. Some combinations don't work, or worked at some point and not later (or worked with Chrome but not Firefox, etc.). This can be quite stressful or even dangerous if this is for an important account and you have no backup plan (⇒ don't). And if the backup options are 1) exploitable in your threat model and 2) not very secure, this obviously reduces or nukes the advantage of using a security key in the first place.

    A typical backup option which is not insecure from my POV if well handled is a set of recovery codes, but for this you need to store them very carefully, safely... and not forget how to access them in x years! In these conditions, setting up a new account requires “some work”.

    And I say all this despite wishing FIDO2 great success, 'cause SIM swapping attacks in particular are quite scary given how much important stuff still depends on codes sent by SMS. 😐

    #FIDO2 #SecurityKeys #authentication #threatModel

  52. Nutzt hier jemand Dropbox über den Safari-Browser auf macOS und hat Google Titan Keys? Lassen sich bei euch die Titan Keys als Security Keys im Dropbox-Account hinterlegen? In Safari klappt die Einbindung nicht. Es kommt die Fehlermeldung "Key Not Found". In Edge konnte ich einen von zwei Titan Keys einrichten. #fido2 #securitykeys #dropbox

  53. Nutzt hier jemand Dropbox über den Safari-Browser auf macOS und hat Google Titan Keys? Lassen sich bei euch die Titan Keys als Security Keys im Dropbox-Account hinterlegen? In Safari klappt die Einbindung nicht. Es kommt die Fehlermeldung "Key Not Found". In Edge konnte ich einen von zwei Titan Keys einrichten. #fido2 #securitykeys #dropbox

  54. Nutzt hier jemand Dropbox über den Safari-Browser auf macOS und hat Google Titan Keys? Lassen sich bei euch die Titan Keys als Security Keys im Dropbox-Account hinterlegen? In Safari klappt die Einbindung nicht. Es kommt die Fehlermeldung "Key Not Found". In Edge konnte ich einen von zwei Titan Keys einrichten. #fido2 #securitykeys #dropbox

  55. Nutzt hier jemand Dropbox über den Safari-Browser auf macOS und hat Google Titan Keys? Lassen sich bei euch die Titan Keys als Security Keys im Dropbox-Account hinterlegen? In Safari klappt die Einbindung nicht. Es kommt die Fehlermeldung "Key Not Found". In Edge konnte ich einen von zwei Titan Keys einrichten. #fido2 #securitykeys #dropbox