home.social

#yubikey — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #yubikey, aggregated by home.social.

  1. One perk of working for Red Hat was the ability to use a self-managed OS. However, this is coming to an end due to compliance requirements. I'm not comfortable with having my personal private keys on a managed system, so I moved my SSH key, GPG key, and electronic signature certificate to a #YubiKey. And damn, it works nicely!

  2. One perk of working for Red Hat was the ability to use a self-managed OS. However, this is coming to an end due to compliance requirements. I'm not comfortable with having my personal private keys on a managed system, so I moved my SSH key, GPG key, and electronic signature certificate to a #YubiKey. And damn, it works nicely!

  3. One perk of working for Red Hat was the ability to use a self-managed OS. However, this is coming to an end due to compliance requirements. I'm not comfortable with having my personal private keys on a managed system, so I moved my SSH key, GPG key, and electronic signature certificate to a #YubiKey. And damn, it works nicely!

  4. One perk of working for Red Hat was the ability to use a self-managed OS. However, this is coming to an end due to compliance requirements. I'm not comfortable with having my personal private keys on a managed system, so I moved my SSH key, GPG key, and electronic signature certificate to a #YubiKey. And damn, it works nicely!

  5. One perk of working for Red Hat was the ability to use a self-managed OS. However, this is coming to an end due to compliance requirements. I'm not comfortable with having my personal private keys on a managed system, so I moved my SSH key, GPG key, and electronic signature certificate to a #YubiKey. And damn, it works nicely!

  6. QoL improvements for #Clav: Pull to sync, wait for key when copying a secret, sync with remote and update credentials.

    I see myself releasing in the next few days. The code will be published under #gpl3orlater. I'm looking for a logo!

    #Clav is a #passwordmanager for #wayland and #android that keeps each secret encrypted to your security key. #slint #yubikey #gopass #foss.

  7. I set out last week to replace my #passwordmanager #gopass. My requirements: keys live on my #yubikey, unlocking one secret doesn't expose the whole vault, native #Wayland UX, per secret fingerprint/pin policy.

    Survey: severely lacking. I was not looking for a project, but the #linux desktop really needs this.

    To stay motivated I raised the bar: native #cosmic and #android too, learning #slint on the way. Not a webview. Secrets done right: constant-time and zeroized.

    Now we're cooking on gas!

  8. Wie dumm ist eigentlich die #Passkey Lösung der #Telekom ?
    Es ist nicht ordentlich #FIDO2 sondern muss auf #Google #Apple oder #Windowshello erfolgen. Mit einem #Yubikey #Token2 oder so funktioniert es nicht. Auch lässt sich nur eine (in Zahlen: 1!) APP oder Gerät für #2FA wie ein #Autenticator hinterlegen...
    Und die #MagentaAI kann einem das nicht beantworten. Nach längerer Konversation bietet sie an mit dem Hinweis "Service Team" an den Support durchzustellen.
    Das klappt natürlich auch nicht. Macht man das, fragt die #AI worum es geht. Ob Internet oder Mobilfunk...

    Das ist ein Konzern, zu dem #TSystems gehört? Geil!

  9. @slink One thing I didn't mention, though: I have various models (YubiKey 5 Series and YubiKey Security Key in both USB-A and USB-C). Whether a given key actually works for FIDO2 or U2F authentication depends on a lot of factors, including in particular the navigator used (Firefox desktop vs. Firefox mobile, Chromium...), the website and whether the key is used via NFC or via USB-A or USB-C. This can be very stressful if the authentication is more than experimenting for you, and if you don't have a known-good, working combination with enough redundancy.

    When I said “no problem so far”, I meant no obviously-hardware problem and no “key used to work but doesn't anymore”. However browser software support and hardware/software compatibility can't be ignored if you rely on the keys!

    #YubiKey #FIDO2 #U2F #SecurityKeys

  10. А сейчас какие-то ключи для двухфакторки возможно в Россию заказать не за сотни денег?
    Хотя бы до 4 тыр, ну или какие сейчас цены на них.

    Я вообще в этой теме не шарю.

    Yubikey 5 стоит в районе 8 тыр, Yubikey SK стоит 4 тыр. ХЗ чем они различаются.

    Я пробовал подобное с флиппером делать, но там файлик с флешки спереть как нефиг. делать

    #hard #u2f #yubikey

  11. I login maybe once a year on my domain registrar's website (Gandi). Something has changed in both Firefox/Chromium since last time, because neither of them accepted any of my Yubikeys anymore: it prompted for a PIN, and I don't remember setting one! (I set one on the OpenPGP application, but that PIN is not accepted for FIDO2).

    Temporarily disabling FIDO2 allowed the login to succeed as documented here: support.yubico.com/s/article/U support.yubico.com/s/article/E
    Note that this does *not* reset FIDO2 (Which IIUC would delete the FIDO U2F key too).
    In that case IIUC it uses FIDO U2F instead of FIDO2 with a PIN. Although this seems like a bug, why doesn't the browser offer me the option of using U2F when I reject providing a FIDO2 PIN? Clearly all this worked fine several years ago when I initially registered the Yubikeys.
    #FIDO2 #Yubikey #U2F

  12. That nerdy urge to configure pam-u2f on work computer :blobCat_devil:

    #nerd #u2f #yubikey

  13. The solution that worked:
    "security.pam.services.doas = {
    u2fAuth = true;
    }"
    Adding this into your configuration file will ensure that doas uses u2f authentication... I'm dumb :neocat_cry_loud:

    #NixOS #linux #LinuxTechTips #U2F #security #yubikey

  14. Fuck #Authy. Fuck it in it's stupid ass. They got rid of the desktop version. Fine. It sucks, but I could deal with it. Then they dropped support for #GrapheneOS. Meaning I'm locked out of everything. Luckily I have a #YubiKey so I can get into most things. I guess it's time to move to something else.

  15. I am looking to buy a set of hardware security keys. The #yubikey seems to be the most common and best documented, but the lack of open source and upgradable firmware puts me off. #nitrokey seems like a better option in this regard, but the design is not as nice. I would also very much like a key that combines both USB-A and C. I have now found the #token2 [PIN+ Dual Release3](token2.com/shop/product/pin-du) which fulfills this, but the company is completely unknown to me, and I haven't found much discussion of their products online, which makes me a bit reluctant. They are, however, a member of the FIDO alliance, which is reassuring. The Linux support for their tools also seem to be second-grade. Does anyone have any experience with them?
    I intend to use the key for FIDO U2F/FIDO2 authentication, as well as TOTP for the services that do not yet support FIDO. I also want to use it for storing my PGP and SSH private keys.
    #U2F #FIDO #FIDO2 #TOTP #hardwaresecuritykey #cybersecurity

  16. I was locked out of my work machine earlier, but it was due to an update of the Yubikey PAM U2F bindings. In case others have the same problem:

    mwop.net/blog/2025-01-15-pam-y

    Frankly, this was a horrible rollout of a security fix, as there's no obvious remediation, and many folks may not have the ability to boot with a rescue drive to workaround the issue.

    #yubikey #u2f

  17. @aleidk I use the keys for stuff like GitHub, my Fediverse account and a Google account. The important stuff, like banking, access to the ISP and mobile phone provider account don't support them, so: nice, but.

    Actually, the expensive #YubiKey Series 5 can also store #OATH #TOTP seeds, which can be useful for a bunch of other accounts: mobile phone brand, Amazon and many more. Note that #TOTP is not #FIDO2 nor #U2F.

  18. I can manage the Yubikey with ykman very well and also delete residential keys. How does this work with trustkeys (trustkeysolutions) for example? Do I have to rely on the manufacturer or is there good open source software available? Or are you paying for the fact that the keys are much cheaper?

    #trustkey #yubikey #fido2 #trustkeysolutions #linux #debian

  19. CyberPiekło zamarzło! #PKO BP wprowadziło obsługę kluczy #Yubikey! 🤯 #2FA #U2F
    Czyżby sektor bankowy w końcu wkraczał w XXI wiek?! Jeszcze niedawno otrzymałem od innego banku komunikat, że hasło do konta nie może być dłuższe niż 16 znaków…

  20. Można klonować klucze Yubikey 5. Podatne są klucze z firmware < 5.7. Wymagany fizyczny dostęp.

    Piekło zamarzło, Yubikey’e zhackowane – tak moglibyśmy opisać wczorajszy komunikat wydany przez Yubico, czyli producenta najpopularniejszych na świecie fizycznych kluczy bezpieczeństwa. Moglibyśmy, ale pomimo że jest w tym nieco prawdy, to nie ma powodu do paniki, przynajmniej dla większości użytkowników popularnych yubikey’ów. Dlaczego nie ma? Zacznijmy od teorii. Badacze z...

    #WBiegu #Atak #EUCLEAK #Infineon #Klonowanie #SideChannel #U2f #Yubikey

    sekurak.pl/mozna-klonowac-kluc

  21. Got SSH #Yubikey logins working natively in Windows Terminal. Pretty slick vs depending on #Kleopatra and Remote Desktop Manager (slow) But still think processes are... Unclear. So, when you create the key, it requires a Yubikey PIN. But when you use it to login, the PIN isn't needed. Guessing it's a setting somewhere. Why wouldn't you require the PIN - because the key pointer file is required (2nd factor)?
    developers.yubico.com/SSH/Secu
    #SysAdmin #MSP #SSH #WSL

  22. Got a new #Google #TitanKey Now I'm using #ChatGPT to see if we can setup FIDO2 authentication to linux servers using the Google Titan, hopefully without needing #Kleopatra Seems like #OpenSSH added FIDO2 support in v8.2 - So this will be interesting. Then we'll see if my #YubiKey can do it...