home.social

#yubikey — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #yubikey, aggregated by home.social.

fetched live
  1. A guide compares 12 passwordless sign-in options for employees, app customers and physical security keys.

    Microsoft scored 4.7/5 and is presented as a practical starting point for companies with suitable Microsoft 365 licences; Okta FastPass scored 4.6/5, while HYPR is positioned as a dedicated platform and Stytch for app teams.

    Pricing models vary—per user, device or active app user—so they are not always directly…

    en.hacks.gr/12-lyseis-syndesis

    #Microsoft #OktaFastPass #YubiKey #PasswordlessLogin

  2. I know we’re not supposed to say nice things about AI, but ChatGPT has an advanced security option where you can go full passwordless using passkeys!

    It disables your password and removes all recovery methods other than some single-use recovery keys.

    Exercise caution if you don’t know what all this is about. But if you do… it’s a rare breath of fresh air.

    One annoyance: You can’t label passkeys. Good luck figuring out what to remove if you lose one.

    #passkey #passkeys #YubiKey #passwordless

  3. YubiKey vs Genérico: A Verdade Sobre Segurança

    🔒 Você sabe a diferença entre um dispositivo de segurança físico de verdade e um genérico? Eu explico aqui!

    💡 O que você precisa saber:
    • YubiKey tem componente seguro, o genérico de 9 dólares não
    • Para uso corporativo, o genérico nem passa no compliance
    • Para autenticação pessoal (senhas, OTP, 2FA), o YubiKey é imbatível

    📌 Guarda esse post para não esquecer!

    Compartilha com quem...

    #SegurançaDigital #YubiKey #Cibersegurança #MorningCrypto

  4. Disable Yubikey from typing gibberish on Mac : r/yubikey

    "Long-pressing a Yubikey Nano will generate a 44-character random-looking string like "ccccccjlkgjlevtdernkbbnrrvhcvgbljgchbgbdbvgk" as an OTP token because it emulates a keyboard.

    This is really annoying for Yubikey Nano, which you can leave plugged into your laptop at all times, and gets sporadically triggered by my lap, which my laptop sits on for a long time. I wanted to disable this.

    Unfortunately, Yubikey Manager is deprecated, so the existing Reddit documentation doesn't help.

    Instea..."

    https://www.reddit.com/r/yubikey/comments/1k6k5pv/disable_yubikey_from_typing_gibberish_on_mac/

    #security #tools #utils #yubikey

  5. Yubico Authenticator App for Desktop and Mobile | Yubico

    "Use the Yubico Authenticator for Desktop on your Windows, Mac, or Linux computers to generate OATH credentials on your YubiKeys."

    https://www.yubico.com/products/yubico-authenticator/

    #security #tools #utils #yubikey

  6. yubikey-manager

    "Python 3.10 (or later) library and command line tool for configuring a YubiKey. If you’re looking for a graphical application, check out Yubico Authenticator.

    tl;dr: to disable the keyboard oops every time I hit the yubikey: brew install ykman && ykman config usb --disable otp"

    https://developers.yubico.com/yubikey-manager/

    #apps #tools #utils #yubikey

  7. I just wanted to call out this guide: github.com/drduh/YubiKey-Guide

    If you're trying to set up hardware level security using yubikeys, it is invaluable. It takes some time and preparation, but the results are that you have a system where you can definitively say that your code is signed by you, your connections are authenticated as being yours, and nobody can use your digital identity but you. Even if you leave the YubiKey in the computer all the time, as long as you've turned on mandatory touch to unlock. It's really nice.

    #security #yubikey

  8. Warum will #Windows eigentlich #TPM s ?

    Euer Rechner funktioniert noch, aber für #Windows11 reicht es plötzlich nicht mehr?

    Eine der Anforderungen heißt TPM 2.0. Ich wollte wissen, was dieses kleine Kryptografie-System tatsächlich schützt – und warum #Microsoft es zur Pflicht macht.

    Kapitel:
    00:00 Warum Windows auf TPM besteht
    01:42 Was ist ein TPM?
    02:43 Ein gestohlener #Laptop und #BitLocker
    06:15 Wie BitLocker seine Schlüssel schützt
    09:00 #SecureBoot: Was darf starten?
    11:02 #Measured Boot: Was wurde gestartet?
    13:21 PCRs: Messwerte, Reihenfolge und Ereignisprotokoll
    16:42 Wann das TPM den Schlüssel freigibt
    18:58 Warum plötzlich der #Wiederherstellungsschlüssel nötig ist
    21:02 Wo der TPM-Schutz aufhört
    22:17 Warum kein #YubiKey?
    23:36 TPM 2.0 und Angriffe
    24:46 Wer verdient an der TPM-Pflicht?
    25:28 Attestierung: Was Firmen über den Rechner erfahren
    28:34 Wer entscheidet über meinen eigenen Rechner?

    tube.the-morpheus.de/c/the_mor

    youtube.com/watch?v=VynV53qFgMY

    @TheMorpheus

  9. I don't get the point of YubiKey and other hardware security keys. Can someone explain it to me? /genq

    #yubikey #security #2fa

  10. OpenSSH 8.2+ supports FIDO2 sk-ssh-ed25519 keys. Private key stays on your YubiKey/SoloKey, signing via CTAP2. No key exfiltration. Setup guide: valtersit.com/vault/hardwareba #ssh #fido2 #yubikey

  11. Reminder for those of you who use physical #SecurityKey like a #Yubikey as your second factor: you trigger it by touching it. Your fingers have dirt and oils on them. Over time the conductive surfaces get covered.

    Twice so far this year I've had different security keys stop working. One just the touch. The other touch AND detection. Both were fixed by taking them out, wiping the conductors off with isopropanol and letting it dry completely before plugging it back in.

  12. 🥰 posteo.de hat still und heimlich #passkeys eingeführt:
    posteo.de/hilfe/passkey-erstel
    Meinen #Yubikey konnte ich auf #MacOS und #Android (mit #Authnkey) leider nicht hinzufügen. #KeePassDX hat aber funktioniert.
    #posteo #passkey

  13. One perk of working for Red Hat was the ability to use a self-managed OS. However, this is coming to an end due to compliance requirements. I'm not comfortable with having my personal private keys on a managed system, so I moved my SSH key, GPG key, and electronic signature certificate to a #YubiKey. And damn, it works nicely!

  14. SSH brute-force attacks run continuously against every public server. Most Linux servers still default to passwords or static SSH keys — both have known weaknesses. Passwords fall to credential stuffing and GPU clusters in minutes; static keys stay unchanged until someone rotates them by hand.

    admindocs.de/en/server-environ

    #linux #security #ssh #fido2 #yubikey #crowdsec #hardening #sysadmin #linuxadmin #linuxsecurity

  15. QoL improvements for #Clav: Pull to sync, wait for key when copying a secret, sync with remote and update credentials.

    I see myself releasing in the next few days. The code will be published under #gpl3orlater. I'm looking for a logo!

    #Clav is a #passwordmanager for #wayland and #android that keeps each secret encrypted to your security key. #slint #yubikey #gopass #foss.

  16. Tired of constant password prompts and manual SSH key entries? I'm breaking down how IMMOROCK and YubiKey can level up your desktop security and streamline your workflow. 💻

    Check out the new video to see how these tools handle 2FA and secure data entry.

    #IMMOROCK #YubiKey #CyberSecurity

    youtube.com/watch?v=5h5GjdEaW3o

  17. Tired of constant password prompts and manual SSH key entries? I'm breaking down how IMMOROCK stacks up against YubiKey to level up your desktop security and 2FA management. A must-watch for any dev looking to streamline their workflow. 💻

    Check out the new video.

    #IMMOROCK #YubiKey #CyberSecurity

    youtube.com/watch?v=p3lLroUcbOs

  18. Ich bin ohne #Smartcard in den #GnuPG-Kaninchenbau gestiegen, an der Kreuzung #Nitrokey und #Yubikey falsch abgebogen, nur um mich Stunden später im Nachbarbau für #Debian-#Paketierung wiederzufinden.

    Soweit ein ganz normales Wochenende.

  19. Was going through my old posts on my old fediverse account and found the open source small low profile yubikey alternatives request post. Before I lose them again, here were the top candidates:

    only key:
    https://onlykey.io/products/onlykey-duo-dual-usb-c-and-usb-a-security-key

    Token2:
    https://www.token2.com/shop/product/pin-mini-c-release3-1-fido2-u2f-and-totp-security-key-with-pin-complexity

    #token2 #yubikey #onlykey

  20. @moschehaus Made some progress this we. Most of the setup works: Clone a repo, list the recipients used by the repo and import the age identities in the #yubikey #PIV on both #cosmic and #android both using #slint.

    The critical paths now work, next up:
    - Decrypt using the key in the PIV.
    - Prompt to import keys during setup.
    - Prompt to import their SSH key for cloning.

    The first release will be a read-only vault you can use to unlock and audit secrets.

    #Clav #passwordmanager

  21. I set out last week to replace my #passwordmanager #gopass. My requirements: keys live on my #yubikey, unlocking one secret doesn't expose the whole vault, native #Wayland UX, per secret fingerprint/pin policy.

    Survey: severely lacking. I was not looking for a project, but the #linux desktop really needs this.

    To stay motivated I raised the bar: native #cosmic and #android too, learning #slint on the way. Not a webview. Secrets done right: constant-time and zeroized.

    Now we're cooking on gas!

  22. Wie dumm ist eigentlich die #Passkey Lösung der #Telekom ?
    Es ist nicht ordentlich #FIDO2 sondern muss auf #Google #Apple oder #Windowshello erfolgen. Mit einem #Yubikey #Token2 oder so funktioniert es nicht. Auch lässt sich nur eine (in Zahlen: 1!) APP oder Gerät für #2FA wie ein #Autenticator hinterlegen...
    Und die #MagentaAI kann einem das nicht beantworten. Nach längerer Konversation bietet sie an mit dem Hinweis "Service Team" an den Support durchzustellen.
    Das klappt natürlich auch nicht. Macht man das, fragt die #AI worum es geht. Ob Internet oder Mobilfunk...

    Das ist ein Konzern, zu dem #TSystems gehört? Geil!

  23. This #Yubico #YubiKey Standard from approximately 2012 was on my personal key ring ever since on a daily basis. It has been my first FIDO2 token.

    It now ceased to work after approx. 14 years as it's no longer recognized by a computer when plugged in.

    Fortunately, it's been mostly replaced by a newer key months ago. So no data loss. Furthermore, I always had a second token that was registered with the same services anyway.

    That's my personal data point for durability of #FIDO2 #security hardware tokens. Not bad, I'd say. 👍️

    I still prefer FIDO2 HW tokens over #passkeys because HW tokens are not prone to #phishing: karl-voit.at/FIDO2-vs-Passkeys/ (German)

    #2FA #MFA #securitytokens #publicvoit #20241005_FIDO2VsPasskeys

  24. #posteo kann jetzt auch #passkeys. Dies ist sicher ein Schritt in die richtige Richtung.

    Allerdings klappt die Registrierung noch nicht mit #Firefox, weder mit #yubikey noch #keepassxc. Das ist frustrierend, aber wer mit dieser Technologie hantiert, ist Frust wohl gewohnt. Kinderschuhe überall...

    Was aber klappt, ist die Registrierung von yubikey unter #Chromium. Wenn man das gemacht hat, klappt auch der Login unter Firefox.

    Die Begründung erscheint mir noch nicht so 100% motiviert:

    > Wir bieten Passkeys als Passwort-Alternative an, weil sie ein neuer Anmelde-Standard sind und manche Kundinnen und Kunden sie nutzen möchten.

    #security

  25. Never heard about this company before, it lacks some of the features, but it offers mostly everything I am really interested in and seems quite cheap. Fully variant seems sold out at the moment, not sure I really need it though.
    solokeys.com/collections/all/p

  26. Tried to configure proper #2FA on my company's service provider site, as it's set to SMS as default. Found just one button to "configure authenticator app". It displays #QRcode without any code to manually copy.
    Not good, my preferred interface for #YubicoAuthenticator is cli, because I want to properly set touch and touch in it currently works weirdly in phone app.

    So my nerdy ass scanned that code using generic barcode scanner on phone, copied revealed URL containing secret, pasted it to Markor file which was later copied via #Syncthing to my work laptop :blobCat_giggle:

    I just cannot use things as intended...

    #yubikey #nerd #authenticator

  27. Well the idea of Yubikey was cool but in practice it isn't exactly what I needed.

    Not all logins work. PayPal's fucked. Microsoft Account is semi-fucked. I accidentally added a pin to my passkeys, now requiring an additional step with my Yubikey. I can't remove it without wiping all my passkeys!

    I got 2 devices so I could have a back up. I can't just copy one device over to another. It was a pain in the ass to set up 2 keys, one login after another.

    I just want to ditch my phone.

  28. Hi @Tutanota I can’t log in to the Tuta Android app with my YubiKey on @GrapheneOS without Google Play Services. I receive: “WebAuthn NotAllowedError — operation timed out or was not allowed.” How can I log in without installing Google Play Services?
    #Tuta #GrapheneOS #YubiKey

  29. Passkey Defenses Targeted in Novel Attacks

    Researchers at Black Hat USA 2026 revealed a shocking vulnerability in passkey defenses, demonstrating how attackers can bypass FIDO2 cryptography and exploit a flaw in Windows Event Logging Service (CVE-2026-34348) to defeat passkey protections. This security gap was found to allow unauthorized users to access and replay sensitive YubiKey signatures.

    osintsights.com/passkey-defens

    #PasskeyDefenses #Fido2 #Cve202634348 #Windows #Yubikey

  30. I really want my Yubikey's touch command to be physical button in keyboard, no matter how I place it, it isn't ergonomic to reach and press the touch plate.

    I probably could unhook a key from the keyboard, pull a wire somehow from underneath it, that triggers the capacitive touch in Yubikey. It would look yanky, but probably work fine.

    #Yubikey

  31. #Passkeys werden Anfang 2027 die Standard-Anmeldemethode im Microsoft-365-Ökosystem 😎 Wenn ihr euch bisher noch gar nicht damit beschäftigt habt, ist jetzt ein guter Zeitpunkt. Ich habe die meisten Passkeys in #Bitwarden (Software), einige wichtige auf dem #Yubikey (Hardware).

  32. Die Solokeys sind kommentarlos verschickt worden...

    Machen wir es kurz: Fehlerhaft und darum Widerruf erklärt.

    Hab nun 2 x Token2 PIN+ Dual bestellt.

    Kein #solokey, was schade ist. Das Design gefällt mir eigentlich.
    Nun also #Token2.
    Drückt mir die Daumen.

    #fido #fido2 #hardwarekey #yubikey

  33. Protip: When you buy a #YubiKey, consider one with NFC. That just saved my ass due to an broken usb connector 😌

  34. My 3A Mini "broke", the string connection was just torn off, now it is a big hassle to remove the key from USB ports..*sigh*. I guess if I buy another it will be a Nitrokey 3C (No NFC). Are there any other better solutions already? (please no if possible)

  35. Some fun coming for me this weekend. All my parts for my new PC are in. It's a desktop, and it's fairly potent. Gonna slap Ubuntu onto it after assembly, and then I can get down to using it. Lots to sync across from the old PC first, and then it becomes my new homelab/server. Been a long time since I've gotten to build again, and really looking forward to it. My one question for anybody reading: anything better than the yubikey nano? The case will have the key sticking straight out, so the nano reduces my ability to break the port or the key.

    #homelab #linux #yubikey #selfhosted

  36. In the past week, I was mainly busy building these. A simple idea of ditching Bitwarden, turned into a rabbit hole of learning and discovery. Read more on my blog: sourcery.zone/articles/2026/08

    #yubikey #security #bitwarden

Share
Share on Mastodon

Enter the server where you have an account.