#yubikeys — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #yubikeys, aggregated by home.social.
-
Ah, #OpenAI, the beacon of cutting-edge #technology, now insists on turning #ChatGPT into Fort Knox with their shiny new #YubiKeys. Because, obviously, logging into a chatbot *must* involve hardware-backed sorcery to ward off cyber dragons. 🐉🔑 Oh, the paranoia!
https://www.yubico.com/blog/openai-mandates-hardware-backed-passkeys-for-trusted-access-cyber-members-to-log-into-chatgpt-accounts/ #cybersecurity #hardware #HackerNews #ngated -
I've got #LibreWolf installed as a #Flatpak.
Was going to reply that, unfortunately, LibreWolf wouldn't work with my #YubiKeys …then it occurred to me:
#Flatseal > Applications > LibreWolf > Device > All devices > ON
-
-
Leute, wenn ihr für eure Liebsten sinnvolle #Weihnachtsgeschenke sucht, dann überlegt euch, #FIDO2-USB-Tokens zu schenken:
https://karl-voit.at/FIDO2-vs-Passkeys/Es gibt aktuell keine andere Methode, um sich garantiert #Phishing-geschützt anzumelden. #Passkeys haben leider inzwischen auch ein Einfallstor für Phishing bekommen (siehe entsprechende Sektion im Artikel).
#Yubikey als Produkt kann ich nicht mehr voll und ganz empfehlen: siehe FAQs.
#publicvoit #Sicherheit #security #Geschenkidee #Geschenkideen #Geschenke #Yubikeys
-
#Ubuntu24 verweigerte heute nach einem Reboot die Nutzung meines #Yubikeys.
Ich konnte mich als mit #pkcs11 nicht mehr an meinen Servern per ssh anmelden.Eine hängengebliebene Filesystem-Action eines Remote-Filesystems verhinderte offenbar, dass Linux meinen Laptop nicht schlafen schicken konnte... Totem ließ sich nicht beenden vom Kernel... aber das ist eine andere Geschichte. Jedenfalls schaltete sich mein Laptop nicht ab bis der Akku leer war.
In einem Anfall seniler Bettflucht hab ich meinen Laptop hergenommen und wollte checken, warum Friendica nur mehr blurred Vorschaubilder anzeigt (Spoiler, das Debuglog eines anderen Services füllte mir die Platte an...) und mein ssh-agent verweigerte das Hinzufügen des Yubikeys. Standhaft.
Ein Blick ins Journal ergab dann folgende Seltsamkeit:
Sep 12 04:34:02 AET-1931 pcscd[24807]: 99999999 auth.c:143:IsClientAuthorized() Process 36310 (user: 2000) is NOT authorized for action: access_pcsc Sep 12 04:34:02 AET-1931 pcscd[24807]: 00000197 winscard_svc.c:355:ContextThread() Rejected unauthorized PC/SC clientEin Restart von pcscd brachte keine Erlösung.
Ein Reboot übrigens auch nicht.Also weitersuchen. Aufgrund der Recherchen einmal
opensc-tool --list-readers No smart card readers found.Shice... und was sagt gpg?
gpg --card-status gpg: selecting card failed: Kein passendes Gerät gefunden gpg: OpenPGP Karte ist nicht vorhanden: Kein passendes Gerät gefundenDas Journal dazu befragt... scdaemon erkennt meine Smartcards, aber pcscd verweigert meinem User den Zugriff.
Also mal als Root... ja, da liefert opensc-tool meine Smartcards.
Dann eine noch seltsamere Erkenntnis...
In tmux ausgeführt, verweigert pcscd die Abfrage mit opensc-tool, in der normalen Bash gibts aber ein Ergebnis... meine Token sind da.Dann hab ich meinen SafeNet eToken ausprobiert... der ließ sich wunderbar zum ssh-agent hinzufügen... gut, der nutzt aber auch den scdaemon bzw. pcscd nicht (extra Ausnahme in der Config).
Schließlich wurde ich auf bugs.debian.org/cgi-bin/bugrep… fündig. Offenbar wurden bei Polkit Rules entfernt, die es Usern erlauben, pcscd/Smartcards zu nutzen... am 8. September beim Update wurde /usr/share/polkit-1/rules.d/sssd-pcsc.rules so geändert, dass die Rule nur mehr für Root zieht. Da wurde das File zumindest aktualisert.
Und heut erst wurde die Änderung durch den Zwangsreboot schlagend...Die Lösung war auf jeden Fall folgende:
Ich hab ein File /etc/polkit-1/rules.d/40-allow-pcscd.rules# cat 40-allow-pcscd.rules polkit.addRule(function(action, subject) { if ( subject.isInGroup("plugdev") && ( action.id === "org.debian.pcsc-lite.access_pcsc" || action.id === "org.debian.pcsc-lite.access_card" ) ) { return polkit.Result.YES; } return polkit.Result.NOT_HANDLED; });
erstellt und meinen User der Gruppe plugdev hinzugefügt. Ab/Anmelden, damit die Gruppenänderung zieht... und schon konnte ich meinen Yubikey wieder für die Authentifikation für ssh-Verbindungen nutzen.Aber warum gpg am Yubikey nicht mehr funktioniert... bleibt mir auch ein Rätsel.
-
Saw some post about migrating #authenticator apps... and I realised I never used Google app for example. Because when I started configuring #2FA, I already had #Yubikeys :blobcatpeek2:
So I naturally downloaded their Yubico Authenticator to use something I could use, without even thinking. And this was/is my first #OTP app I ever used.
I tried FreeOTP or something similar when it was recommended for some work thing in previous job, but never had a chance to really "feel" that because I changed jobs shortly after.
And now I thought for the first time that my only experience with OTP is when codes aren't device-locked... :blobcatgiggle:
And for me it's absolutely natural state, as things should be. -
I wonder... Am I the only one who quite frequently accidentally puts the #smartphone with #NFC enabled on #Yubikeys and activates factory-set Yubico OTP when trying to simply put my phone on my desk? :blobcatsweat:
It happens ever through few layers of paper sheets - often because of this, when I cannot see keys hidden under paper pile. As I remember one time was through thin notebook. -
Oh, look, another thrilling blog post about creating your own offline PKI system with 3 #YubiKeys and a computer that can barely run Tetris! 😂 Because nothing screams "fun weekend project" like locking yourself in an air-gapped bunker just to feel marginally more secure while the rest of us enjoy the cloud, amirite? ☁️🔒
https://vincent.bernat.ch/en/blog/2025-offline-pki-yubikeys #offlinePKI #security #humor #weekendproject #airgapped #HackerNews #ngated -
People who use hardware security keys: Storing them in geographically diverse locations is a wise move but makes it impossible to quickly onboard. How do you keep track of where you’ve registered each key? A checklist in a spreadsheet is obvious but cumbersome. Is there a better way? (Yes I use passkeys extensively but for certain services like email, iCloud, and my password manager, a hardware option is desirable if not mandatory.) #YubiKey #YubiKeys #FIDO #FIDO2 #FIDOKey #FIDOKeys #Security
-
I've written a new blog post (9000 words) taking a moderately deep dive into "Threat Modeling YubiKeys and Passkeys"
https://yawnbox.is/blog/threat-modeling-yubikeys-and-passkeys/
I greatly welcome feedback as I want to make sure I'm not misrepresenting anything. I want to make it better if it can be improved. I'm happy to be wrong, just please provide details and links!
also, i need a job! if you like my work, maybe you know of something where i'd be a good fit.
#infosec #cybersecurity #IAM #FIDO2 #WebAuthn #YubiKey #YubiKeys #passkey #passkeys #GetFediHired
-
-
Touch Notifications for #YubiKeys https://debblog.philkern.de/2024/10/touch-notifications-for-yubikeys.html
-
Ok, I'm going to fully admit I'm not entirely sure how to use #YubicoAuthenticator amongst multiple #YubiKeys vs, say, #Authy or #GoogleAuthenticator after a year+ of off/on looking to try it out.
Do I need to store the #TOTP seeds on every #YubiKey I own? And they all take up a slot? If so, I'm glad for most high value ones, I've been saving encrypted copies of the initial secret key in my password manager. Is that the way it works, all stored in the keys, and not some DB on each device?
-
#YubiKeys Are a #Security Gold Standard—but They Can Be Cloned
Security researchers have discovered a #cryptographic flaw that leaves the #YubiKey 5 vulnerable to attack.
#privacy -
According to #Yubico, it took six months for a firmware vulnerability that allows cloning of #YubiKeys using #EllipticCurveCryptography to be resolved and responsibly revealed to the public. That's not the problem.
The real problem is there will always be another unpatched vulnerability just around the corner. That's why we need new ways of framing what #cybersecurity should look like in today's modern enterprise. Old-school #defenseindepth still has a place, but businesses must find new ways to reduce the amount of sensitive data that's at risk in a #databreach when all layers of defense are inevitably pierced.
https://www.yubico.com/support/security-advisories/ysa-2024-03/
-
Older #YubiKeys compromised by unpatchable #2FA bug — side-channel #attack is critical, but expensive and difficult to execute
https://www.tomshardware.com/tech-industry/cyber-security/older-yubikeys-compromised-by-unpatchable-2fa-bug-side-channel-attack-is-critical-but-expensive-and-difficult-to-execute -
New #Yubikeys. Needed?
Jan Wildeboer:
https://social.wildeboer.net/@jwildeboer/113075481869359895Edit: It's not that bad. ed25519 is not affected.
-
YubiKeys are vulnerable to cloning attacks thanks to newly discovered side channel.
#YubiKeys #Security #Tech #News #TechNews #AllThingsTech #SecurityKey
-
#YubiKeys are #vulnerable to #cloning attacks thanks to newly discovered side channel
#sidechannel #security #2fa #privacy -
Sembla que han descobert una “vulnerabilitat” a les #Yubikeys, ja que són “clonables”.
#Ciberseguretat #SeguretatDigital #Tecnologia #Autenticació #Privacitat #Hacking #SeguretatInformàtica
Com diu @rysiek, l'atac requereix:
- Obrir físicament la YubiKey
- Accés físic a la YubiKey “mentre s'autentica”
- Equips de laboratori d'electrònica no trivials... Bàsicament, en tots els escenaris possibles, estàs més segur utilitzant una #YubiKey que no utilitzar-ne cap.
-
And this happened... I accidentally left my #yubikey (this one on dogtag chain I always had on me) in friend's house :blobcatsad2:
Now I really feel naked or like I sudenly lost my weapon or my "magic powers". Have to take it back soon because it's very uncomfortable even if technically I have enough backup configurations to use other #yubikeys to access my things (all my devices/accounts are strongly dependent on yubikeys so I made good backups from the beginning). -
Jo vull una d'aquestes per aprovar els #pullrequest de #git a la feina amb dos #yubikeys
-
Some time ago I watched low budget horror movie. Not very mainstream one, I don't even remember title yet. Main character involuntarily became kind of undead and had to wear some magic #amulet. When she was taking it off, she was closer to afterlife dimension and eventually really dead, even if in reversible way.
Currently I feel in similar way after 5 years of wearing one of my #Yubikeys on my neck on dogtag chain. I have it on me really most of time, also when I sleep (not when I wash myself, it would be inconvenient even if it's waterproof). Sometimes I take it off, even for few hours (very rarely) but then it is always few meters from me. And then I feel like I lose connection with some "higher force", source of my "special powers" (or source of my identity? my soul?) or something and it's rather uncomfortable.
So it seems like cryptography and privacy obsession turned me into a #lich :blobcatghost: 💀🧟♀️