home.social

#token2 — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #token2, aggregated by home.social.

  1. Just confirmed: my TOTP seeds live on my Token2 Bio3 key itself.
    The app is just a reader. The seed never leaves the hardware.

    That said — Proton Authenticator looks genuinely excellent.
    If I didn't have a key where the seed lives on it,
    that's where I'd put my seed.

    Gigity.

    #TOTP #2FA #Infosec #ProtonAuth #Token2 #FIDO2

  2. Just confirmed: my TOTP seeds live on my Token2 Bio3 key itself.
    The app is just a reader. The seed never leaves the hardware.

    That said — Proton Authenticator looks genuinely excellent.
    If I didn't have a key where the seed lives on it,
    that's where I'd put my seed.

    Gigity.

    #TOTP #2FA #Infosec #ProtonAuth #Token2 #FIDO2

  3. Just confirmed: my TOTP seeds live on my Token2 Bio3 key itself.
    The app is just a reader. The seed never leaves the hardware.

    That said — Proton Authenticator looks genuinely excellent.
    If I didn't have a key where the seed lives on it,
    that's where I'd put my seed.

    Gigity.

    #TOTP #2FA #Infosec #ProtonAuth #Token2 #FIDO2

  4. Just confirmed: my TOTP seeds live on my Token2 Bio3 key itself.
    The app is just a reader. The seed never leaves the hardware.

    That said — Proton Authenticator looks genuinely excellent.
    If I didn't have a key where the seed lives on it,
    that's where I'd put my seed.

    Gigity.

    #TOTP #2FA #Infosec #ProtonAuth #Token2 #FIDO2

  5. Just confirmed: my TOTP seeds live on my Token2 Bio3 key itself.
    The app is just a reader. The seed never leaves the hardware.

    That said — Proton Authenticator looks genuinely excellent.
    If I didn't have a key where the seed lives on it,
    that's where I'd put my seed.

    Gigity.

    #TOTP #2FA #Infosec #ProtonAuth #Token2 #FIDO2

  6. @Cloudsincoffee

    do they work on Linux for LUKS etc. - can you use the same package yubikey-luks? I'm currently using Yubikey, but always open for change, if it is not too difficult.

    #Yubikey #Token2 #LUKS #Linux #FIDO2 #MFA

  7. Seeing the latest video hit #1 in the studio dashboard is a great reminder of why I started Terminal Tilt.

    780 views in less than 7 hours on a video about hardware security keys? You all prove there’s a massive hunger for privacy and right-to-repair content.

    Huge thank you to everyone who watched and shared!

    If you haven't watched it yet, its available here: youtube.com/watch?v=lQlN84gEb9c

    #DigitalSovereignty #Privacy #OpSec #RightToRepair #OpenSource #Token2 #Yubikey #Nitrokey #TerminalTIlt

  8. 🚨 New Video: Protecting You From Yourself - The Token2 Review

    We have looked at the industry standard (YubiKey) and the philosophical idealist (Nitrokey). Today, we’re looking at the aggressor: Token2.

    The PIN+ Dual Release 3.3 and the Bio3 come in at nearly half the price of the competition, but there is a catch. This Swiss company doesn't care about convenience; they care about correctness. From hardware-enforced complex PINs to a literal war on legacy TOTP codes, Token2 assumes your ego is your biggest vulnerability.

    Is this cynical, locked-down approach exactly what we need for true digital sovereignty, or is the clunky user experience a dealbreaker? Let's find out if this is the ultimate punk rock choice for your threat model.

    Part 5 of the Sovereign Authentication series.

    100% human made. #NoAI :NoAI:

    ▶️ YouTube: youtube.com/watch?v=lQlN84gEb9c
    📺 PeerTube: gnulinux.tube/w/fZbyKea1b6QJVQ

    💬 Join our sovereign community on Stoat: stt.gg/GgB6HBTv
    ☕ Support the mission: liberapay.com/terminaltilt
    🤝 Become a channel member: youtube.com/@TerminalTilt/join

    #TerminalTilt #NoAI #Privacy #Security #PasswordManager #Token2 #Nitrokey #Yubikey #Yubico #FOSS #OpenSource #Linux #Cybersecurity #SelfHosted #DeGoogle #DigitalSovereignty #QueerCreator #DisabledCreator #HumanMade #TechEthics

  9. Terminal Tilt: Upcoming Schedule

    Tomorrow: Divoom Pixoo 64 Review.

    Monday, Feb 23: Sovereign Authentication (Part 3) – The YubiKey 5 Series Review.

    Feb 26: Keychron Q1 V2 – 4 Years Later.

    March 2: Sovereign Authentication (Part 4) – Nitrokey 3A NFC Review.

    March 5: Epomaker TH99 Pro Review.

    March 9: Sovereign Authentication (Part 5) - Token2 Keys Review

    youtube.com/@TerminalTilt

    #TerminalTilt #DigitalSovereignty #RightToRepair #Privacy #SelfHosted #YubiKey #Nitrokey #Keychron #Epomaker #Token2 #Divoom #Pixoo64 #DivoomPixoo64 #Zettlr

  10. I have officially deleted my Amazon account and cut ties with their ecosystem entirely. For a long time, the convenience of Prime felt like a necessary evil, especially since they have a warehouse in my city and can do same day shipping. But I can no longer reconcile the big tech giant's behavior with the values I promote at Terminal Tilt. As a privacy advocate and FOSS supporter, continuing to feed the machine feels increasingly hypocritical.

    Ethically, their treatment of labor is indefensible. Between the terrible warehouse conditions and the dark patterns designed to make canceling subscriptions nearly impossible, it is clear they view both employees and customers as numbers to be exploited, with contempt. Their anti-competitive practices have done irreparable harm to small businesses and independent creators who are forced to play in a rigged sandbox.

    As an FSF and EFF member, I believe privacy is a fundamental right. Amazon's business model relies on massive data harvesting and a huge surveillance network that I simply do not want to be a part of. Deleting my account is my way of reclaiming my digital sovereignty and refusing to let my personal data be a product in their inventory.

    The change also affects how I handle Terminal Tilt going forward. I am officially ending the use of Amazon affiliate links for the channel. While the links are a standard revenue stream for most creators, I refuse to track my audience into the Amazon ecosystem just for a small commission. I would rather the channel grow slower and more honestly than profit from a company that actively works against user freedom. Convenience is the enemy of sovereignty.

    When I review products now, whether it is the security keys from @nitrokey , @yubico , and Token2 or open source hardware, I will provide links to direct manufacturers or ethical, privacy-respecting retailers instead. Convenience should never be the primary metric for our choices.

    If you want to support my work on Linux, privacy, and the #NoAI movement, I encourage you to use my LiberaPay or Ko-Fi links. Supporting creators directly ensures that the content remains independent and free from the influence of the Epstein class and corporate overlords. You can find all my direct support links on my self-hosted Linkstack: links.terminaltilt.com

    It feels good to be out. It is time to prioritize people and principles over same-day shipping.

    #DeleteAmazon #AmazonBoycott #Amazon #Privacy #FOSS #Linux #TerminalTilt #EthicalConsumerism #Ethics #InfoSec #Yubikey #Nitrokey #Token2 #2FA #MFA #Surveillance #SurveillanceCapitalism #DigitalSovereignty #SelfHosting

  11. 🚨 New Video: Stop Trusting Google With Your Keys (Part 1 of 5: Sovereign Authentication)

    Convenience is the enemy of sovereignty.

    You don't own your phone number; you lease it. If you rely on SMS or cloud-synced apps like Google Authenticator, you aren't securing your account. You are handing the keys to a landlord.

    In the premiere of this new series, we break down the 4 Tiers of Authentication. We explain why SMS is a disaster, why I deleted Google Authenticator, and why hardware keys are the only way to truly own your access.

    100% Human made. #NoAI :NoAI:

    ▶️ YouTube: youtube.com/watch?v=7Y8Q9LnSQxM

    📺 PeerTube: gnulinux.tube/w/hbNHh7TjUNiCa9

    📝 Blog Post: terminaltilt.com/2026/02/09/st

    Support the mission: ☕ ko-fi.com/terminaltilt | liberapay.com/terminaltilt

    #TerminalTilt #NoAI #Security #Privacy #2FA #MFA #Yubikey #Nitrokey #Token2 #FOSS #Linux #Cybersecurity #SelfHosted #Google #DeGoogle #DigitalSovereignty #QueerCreator #DisabledCreator #HumanMade #TechEthics

  12. I wonder, are there any working SSH clients on iOS that can handle ed255519_sk keys?

    (That’s the variant where you have a public and private key part however the private key links to a residential key on an external FIDO2 security token. You plug in the token or use NFC, enter the pin and confirm with a touch)

    #ssh #fido2 #token2 #iOS #ed25519

  13. #Passkeys are everywhere nowadays
    #windowshello #fido2 #androidpasskeys #token2

    I myself switch to passkeys for any supported service. Have a look here if your services are supported: passkeys.io/who-supports-passk

    Understanding why they're more secure and why they are able to be used in so many different shapes is not as easy.

    Computerphile just released a greate video about the technology and the authentic flow:
    youtube.com/watch?v=xYfiOnufBSk

  14. Durch den #CLT2025 Talk zu Passwortlose Logins mit #PassKeys media.ccc.de/v/clt25-188-passw bin ich auf die #Token2 PIN+ #Securitykeys aufmerksam geworden token2.com/shop/category/pin-p
    Die DualPort Keys sind wohl sehr nützlich, haben 300 Resident Keys, kommen mit Hülle und kosten nur 26€.
    Zur Wasserfestigkeit finde ich leider nichts.
    Würde mich über Erfahrungsberichte freuen.
    #FIDO2

  15. I am looking to buy a set of hardware security keys. The #yubikey seems to be the most common and best documented, but the lack of open source and upgradable firmware puts me off. #nitrokey seems like a better option in this regard, but the design is not as nice. I would also very much like a key that combines both USB-A and C. I have now found the #token2 [PIN+ Dual Release3](token2.com/shop/product/pin-du) which fulfills this, but the company is completely unknown to me, and I haven't found much discussion of their products online, which makes me a bit reluctant. They are, however, a member of the FIDO alliance, which is reassuring. The Linux support for their tools also seem to be second-grade. Does anyone have any experience with them?
    I intend to use the key for FIDO U2F/FIDO2 authentication, as well as TOTP for the services that do not yet support FIDO. I also want to use it for storing my PGP and SSH private keys.
    #U2F #FIDO #FIDO2 #TOTP #hardwaresecuritykey #cybersecurity