home.social

#yubikeys — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #yubikeys, aggregated by home.social.

fetched live
  1. Ah, #OpenAI, the beacon of cutting-edge #technology, now insists on turning #ChatGPT into Fort Knox with their shiny new #YubiKeys. Because, obviously, logging into a chatbot *must* involve hardware-backed sorcery to ward off cyber dragons. 🐉🔑 Oh, the paranoia!
    yubico.com/blog/openai-mandate #cybersecurity #hardware #HackerNews #ngated

  2. Ah, #OpenAI, the beacon of cutting-edge #technology, now insists on turning #ChatGPT into Fort Knox with their shiny new #YubiKeys. Because, obviously, logging into a chatbot *must* involve hardware-backed sorcery to ward off cyber dragons. 🐉🔑 Oh, the paranoia!
    yubico.com/blog/openai-mandate #cybersecurity #hardware #HackerNews #ngated

  3. Ah, #OpenAI, the beacon of cutting-edge #technology, now insists on turning #ChatGPT into Fort Knox with their shiny new #YubiKeys. Because, obviously, logging into a chatbot *must* involve hardware-backed sorcery to ward off cyber dragons. 🐉🔑 Oh, the paranoia!
    yubico.com/blog/openai-mandate #cybersecurity #hardware #HackerNews #ngated

  4. Ah, #OpenAI, the beacon of cutting-edge #technology, now insists on turning #ChatGPT into Fort Knox with their shiny new #YubiKeys. Because, obviously, logging into a chatbot *must* involve hardware-backed sorcery to ward off cyber dragons. 🐉🔑 Oh, the paranoia!
    yubico.com/blog/openai-mandate #cybersecurity #hardware #HackerNews #ngated

  5. Ah, #OpenAI, the beacon of cutting-edge #technology, now insists on turning #ChatGPT into Fort Knox with their shiny new #YubiKeys. Because, obviously, logging into a chatbot *must* involve hardware-backed sorcery to ward off cyber dragons. 🐉🔑 Oh, the paranoia!
    yubico.com/blog/openai-mandate #cybersecurity #hardware #HackerNews #ngated

  6. Hey #Paypal you want proper security supports #Yubikeys and now shove your constant Passkey nagging up your arse!

  7. @Nymnympseudonymm

    I've got #LibreWolf installed as a #Flatpak.

    Was going to reply that, unfortunately, LibreWolf wouldn't work with my #YubiKeys …then it occurred to me:

    #Flatseal > Applications > LibreWolf > Device > All devices > ON

    LIbreWolf Flatpak now does #FIDO2 on #Linux!

  8. @Nymnympseudonymm

    I've got #LibreWolf installed as a #Flatpak.

    Was going to reply that, unfortunately, LibreWolf wouldn't work with my #YubiKeys …then it occurred to me:

    #Flatseal > Applications > LibreWolf > Device > All devices > ON

    LIbreWolf Flatpak now does #FIDO2 on #Linux!

  9. @Nymnympseudonymm

    I've got #LibreWolf installed as a #Flatpak.

    Was going to reply that, unfortunately, LibreWolf wouldn't work with my #YubiKeys …then it occurred to me:

    #Flatseal > Applications > LibreWolf > Device > All devices > ON

    LIbreWolf Flatpak now does #FIDO2 on #Linux!

  10. @Nymnympseudonymm

    I've got #LibreWolf installed as a #Flatpak.

    Was going to reply that, unfortunately, LibreWolf wouldn't work with my #YubiKeys …then it occurred to me:

    #Flatseal > Applications > LibreWolf > Device > All devices > ON

    LIbreWolf Flatpak now does #FIDO2 on #Linux!

  11. Bought my first #Yubikeys today.

    Seems like a good idea.

  12. Bought my first #Yubikeys today.

    Seems like a good idea.

  13. Bought my first #Yubikeys today.

    Seems like a good idea.

  14. Bought my first #Yubikeys today.

    Seems like a good idea.

  15. Bought my first #Yubikeys today.

    Seems like a good idea.

  16. With the existence/acceptance of #PassKeys, is it still worth using physical #Fido keys (aka #YubiKeys) for online accounts?
    #poll #security 🗳️

  17. With the existence/acceptance of #PassKeys, is it still worth using physical #Fido keys (aka #YubiKeys) for online accounts?
    #poll #security 🗳️

  18. With the existence/acceptance of #PassKeys, is it still worth using physical #Fido keys (aka #YubiKeys) for online accounts?
    #poll #security 🗳️

  19. With the existence/acceptance of #PassKeys, is it still worth using physical #Fido keys (aka #YubiKeys) for online accounts?
    #poll #security 🗳️

  20. With the existence/acceptance of #PassKeys, is it still worth using physical #Fido keys (aka #YubiKeys) for online accounts?
    #poll #security 🗳️

  21. Leute, wenn ihr für eure Liebsten sinnvolle #Weihnachtsgeschenke sucht, dann überlegt euch, #FIDO2-USB-Tokens zu schenken:
    karl-voit.at/FIDO2-vs-Passkeys/

    Es gibt aktuell keine andere Methode, um sich garantiert #Phishing-geschützt anzumelden. #Passkeys haben leider inzwischen auch ein Einfallstor für Phishing bekommen (siehe entsprechende Sektion im Artikel).

    #Yubikey als Produkt kann ich nicht mehr voll und ganz empfehlen: siehe FAQs.

    #publicvoit #Sicherheit #security #Geschenkidee #Geschenkideen #Geschenke #Yubikeys

  22. Leute, wenn ihr für eure Liebsten sinnvolle #Weihnachtsgeschenke sucht, dann überlegt euch, #FIDO2-USB-Tokens zu schenken:
    karl-voit.at/FIDO2-vs-Passkeys/

    Es gibt aktuell keine andere Methode, um sich garantiert #Phishing-geschützt anzumelden. #Passkeys haben leider inzwischen auch ein Einfallstor für Phishing bekommen (siehe entsprechende Sektion im Artikel).

    #Yubikey als Produkt kann ich nicht mehr voll und ganz empfehlen: siehe FAQs.

    #publicvoit #Sicherheit #security #Geschenkidee #Geschenkideen #Geschenke #Yubikeys

  23. Leute, wenn ihr für eure Liebsten sinnvolle #Weihnachtsgeschenke sucht, dann überlegt euch, #FIDO2-USB-Tokens zu schenken:
    karl-voit.at/FIDO2-vs-Passkeys/

    Es gibt aktuell keine andere Methode, um sich garantiert #Phishing-geschützt anzumelden. #Passkeys haben leider inzwischen auch ein Einfallstor für Phishing bekommen (siehe entsprechende Sektion im Artikel).

    #Yubikey als Produkt kann ich nicht mehr voll und ganz empfehlen: siehe FAQs.

    #publicvoit #Sicherheit #security #Geschenkidee #Geschenkideen #Geschenke #Yubikeys

  24. Leute, wenn ihr für eure Liebsten sinnvolle #Weihnachtsgeschenke sucht, dann überlegt euch, #FIDO2-USB-Tokens zu schenken:
    karl-voit.at/FIDO2-vs-Passkeys/

    Es gibt aktuell keine andere Methode, um sich garantiert #Phishing-geschützt anzumelden. #Passkeys haben leider inzwischen auch ein Einfallstor für Phishing bekommen (siehe entsprechende Sektion im Artikel).

    #Yubikey als Produkt kann ich nicht mehr voll und ganz empfehlen: siehe FAQs.

    #publicvoit #Sicherheit #security #Geschenkidee #Geschenkideen #Geschenke #Yubikeys

  25. Leute, wenn ihr für eure Liebsten sinnvolle #Weihnachtsgeschenke sucht, dann überlegt euch, #FIDO2-USB-Tokens zu schenken:
    karl-voit.at/FIDO2-vs-Passkeys/

    Es gibt aktuell keine andere Methode, um sich garantiert #Phishing-geschützt anzumelden. #Passkeys haben leider inzwischen auch ein Einfallstor für Phishing bekommen (siehe entsprechende Sektion im Artikel).

    #Yubikey als Produkt kann ich nicht mehr voll und ganz empfehlen: siehe FAQs.

    #publicvoit #Sicherheit #security #Geschenkidee #Geschenkideen #Geschenke #Yubikeys

  26. #Ubuntu24 verweigerte heute nach einem Reboot die Nutzung meines #Yubikeys.
    Ich konnte mich als mit #pkcs11 nicht mehr an meinen Servern per ssh anmelden.

    Eine hängengebliebene Filesystem-Action eines Remote-Filesystems verhinderte offenbar, dass Linux meinen Laptop nicht schlafen schicken konnte... Totem ließ sich nicht beenden vom Kernel... aber das ist eine andere Geschichte. Jedenfalls schaltete sich mein Laptop nicht ab bis der Akku leer war.

    In einem Anfall seniler Bettflucht hab ich meinen Laptop hergenommen und wollte checken, warum Friendica nur mehr blurred Vorschaubilder anzeigt (Spoiler, das Debuglog eines anderen Services füllte mir die Platte an...) und mein ssh-agent verweigerte das Hinzufügen des Yubikeys. Standhaft.

    Ein Blick ins Journal ergab dann folgende Seltsamkeit:

    Sep 12 04:34:02 AET-1931 pcscd[24807]: 99999999 auth.c:143:IsClientAuthorized() Process 36310 (user: 2000) is NOT authorized for action: access_pcsc
    Sep 12 04:34:02 AET-1931 pcscd[24807]: 00000197 winscard_svc.c:355:ContextThread() Rejected unauthorized PC/SC client

    Ein Restart von pcscd brachte keine Erlösung.
    Ein Reboot übrigens auch nicht.

    Also weitersuchen. Aufgrund der Recherchen einmal

    opensc-tool --list-readers
    No smart card readers found.

    Shice... und was sagt gpg?

    gpg --card-status
    gpg: selecting card failed: Kein passendes Gerät gefunden
    gpg: OpenPGP Karte ist nicht vorhanden: Kein passendes Gerät gefunden

    Das Journal dazu befragt... scdaemon erkennt meine Smartcards, aber pcscd verweigert meinem User den Zugriff.

    Also mal als Root... ja, da liefert opensc-tool meine Smartcards.

    Dann eine noch seltsamere Erkenntnis...
    In tmux ausgeführt, verweigert pcscd die Abfrage mit opensc-tool, in der normalen Bash gibts aber ein Ergebnis... meine Token sind da.

    Dann hab ich meinen SafeNet eToken ausprobiert... der ließ sich wunderbar zum ssh-agent hinzufügen... gut, der nutzt aber auch den scdaemon bzw. pcscd nicht (extra Ausnahme in der Config).

    Schließlich wurde ich auf bugs.debian.org/cgi-bin/bugrep… fündig. Offenbar wurden bei Polkit Rules entfernt, die es Usern erlauben, pcscd/Smartcards zu nutzen... am 8. September beim Update wurde /usr/share/polkit-1/rules.d/sssd-pcsc.rules so geändert, dass die Rule nur mehr für Root zieht. Da wurde das File zumindest aktualisert.
    Und heut erst wurde die Änderung durch den Zwangsreboot schlagend...

    Die Lösung war auf jeden Fall folgende:
    Ich hab ein File /etc/polkit-1/rules.d/40-allow-pcscd.rules

    # cat 40-allow-pcscd.rules 
    polkit.addRule(function(action, subject) {
        if (
            subject.isInGroup("plugdev")
            && (
                action.id === "org.debian.pcsc-lite.access_pcsc"
                || action.id === "org.debian.pcsc-lite.access_card"
            )
        ) {
            return polkit.Result.YES;
        }
    
        return polkit.Result.NOT_HANDLED;
    });

    erstellt und meinen User der Gruppe plugdev hinzugefügt. Ab/Anmelden, damit die Gruppenänderung zieht... und schon konnte ich meinen Yubikey wieder für die Authentifikation für ssh-Verbindungen nutzen.

    Aber warum gpg am Yubikey nicht mehr funktioniert... bleibt mir auch ein Rätsel.

  27. #Ubuntu24 verweigerte heute nach einem Reboot die Nutzung meines #Yubikeys.
    Ich konnte mich als mit #pkcs11 nicht mehr an meinen Servern per ssh anmelden.

    Eine hängengebliebene Filesystem-Action eines Remote-Filesystems verhinderte offenbar, dass Linux meinen Laptop nicht schlafen schicken konnte... Totem ließ sich nicht beenden vom Kernel... aber das ist eine andere Geschichte. Jedenfalls schaltete sich mein Laptop nicht ab bis der Akku leer war.

    In einem Anfall seniler Bettflucht hab ich meinen Laptop hergenommen und wollte checken, warum Friendica nur mehr blurred Vorschaubilder anzeigt (Spoiler, das Debuglog eines anderen Services füllte mir die Platte an...) und mein ssh-agent verweigerte das Hinzufügen des Yubikeys. Standhaft.

    Ein Blick ins Journal ergab dann folgende Seltsamkeit:

    Sep 12 04:34:02 AET-1931 pcscd[24807]: 99999999 auth.c:143:IsClientAuthorized() Process 36310 (user: 2000) is NOT authorized for action: access_pcsc
    Sep 12 04:34:02 AET-1931 pcscd[24807]: 00000197 winscard_svc.c:355:ContextThread() Rejected unauthorized PC/SC client

    Ein Restart von pcscd brachte keine Erlösung.
    Ein Reboot übrigens auch nicht.

    Also weitersuchen. Aufgrund der Recherchen einmal

    opensc-tool --list-readers
    No smart card readers found.

    Shice... und was sagt gpg?

    gpg --card-status
    gpg: selecting card failed: Kein passendes Gerät gefunden
    gpg: OpenPGP Karte ist nicht vorhanden: Kein passendes Gerät gefunden

    Das Journal dazu befragt... scdaemon erkennt meine Smartcards, aber pcscd verweigert meinem User den Zugriff.

    Also mal als Root... ja, da liefert opensc-tool meine Smartcards.

    Dann eine noch seltsamere Erkenntnis...
    In tmux ausgeführt, verweigert pcscd die Abfrage mit opensc-tool, in der normalen Bash gibts aber ein Ergebnis... meine Token sind da.

    Dann hab ich meinen SafeNet eToken ausprobiert... der ließ sich wunderbar zum ssh-agent hinzufügen... gut, der nutzt aber auch den scdaemon bzw. pcscd nicht (extra Ausnahme in der Config).

    Schließlich wurde ich auf bugs.debian.org/cgi-bin/bugrep… fündig. Offenbar wurden bei Polkit Rules entfernt, die es Usern erlauben, pcscd/Smartcards zu nutzen... am 8. September beim Update wurde /usr/share/polkit-1/rules.d/sssd-pcsc.rules so geändert, dass die Rule nur mehr für Root zieht. Da wurde das File zumindest aktualisert.
    Und heut erst wurde die Änderung durch den Zwangsreboot schlagend...

    Die Lösung war auf jeden Fall folgende:
    Ich hab ein File /etc/polkit-1/rules.d/40-allow-pcscd.rules

    # cat 40-allow-pcscd.rules 
    polkit.addRule(function(action, subject) {
        if (
            subject.isInGroup("plugdev")
            && (
                action.id === "org.debian.pcsc-lite.access_pcsc"
                || action.id === "org.debian.pcsc-lite.access_card"
            )
        ) {
            return polkit.Result.YES;
        }
    
        return polkit.Result.NOT_HANDLED;
    });

    erstellt und meinen User der Gruppe plugdev hinzugefügt. Ab/Anmelden, damit die Gruppenänderung zieht... und schon konnte ich meinen Yubikey wieder für die Authentifikation für ssh-Verbindungen nutzen.

    Aber warum gpg am Yubikey nicht mehr funktioniert... bleibt mir auch ein Rätsel.

  28. #Ubuntu24 verweigerte heute nach einem Reboot die Nutzung meines #Yubikeys.
    Ich konnte mich als mit #pkcs11 nicht mehr an meinen Servern per ssh anmelden.

    Eine hängengebliebene Filesystem-Action eines Remote-Filesystems verhinderte offenbar, dass Linux meinen Laptop nicht schlafen schicken konnte... Totem ließ sich nicht beenden vom Kernel... aber das ist eine andere Geschichte. Jedenfalls schaltete sich mein Laptop nicht ab bis der Akku leer war.

    In einem Anfall seniler Bettflucht hab ich meinen Laptop hergenommen und wollte checken, warum Friendica nur mehr blurred Vorschaubilder anzeigt (Spoiler, das Debuglog eines anderen Services füllte mir die Platte an...) und mein ssh-agent verweigerte das Hinzufügen des Yubikeys. Standhaft.

    Ein Blick ins Journal ergab dann folgende Seltsamkeit:

    Sep 12 04:34:02 AET-1931 pcscd[24807]: 99999999 auth.c:143:IsClientAuthorized() Process 36310 (user: 2000) is NOT authorized for action: access_pcsc
    Sep 12 04:34:02 AET-1931 pcscd[24807]: 00000197 winscard_svc.c:355:ContextThread() Rejected unauthorized PC/SC client

    Ein Restart von pcscd brachte keine Erlösung.
    Ein Reboot übrigens auch nicht.

    Also weitersuchen. Aufgrund der Recherchen einmal

    opensc-tool --list-readers
    No smart card readers found.

    Shice... und was sagt gpg?

    gpg --card-status
    gpg: selecting card failed: Kein passendes Gerät gefunden
    gpg: OpenPGP Karte ist nicht vorhanden: Kein passendes Gerät gefunden

    Das Journal dazu befragt... scdaemon erkennt meine Smartcards, aber pcscd verweigert meinem User den Zugriff.

    Also mal als Root... ja, da liefert opensc-tool meine Smartcards.

    Dann eine noch seltsamere Erkenntnis...
    In tmux ausgeführt, verweigert pcscd die Abfrage mit opensc-tool, in der normalen Bash gibts aber ein Ergebnis... meine Token sind da.

    Dann hab ich meinen SafeNet eToken ausprobiert... der ließ sich wunderbar zum ssh-agent hinzufügen... gut, der nutzt aber auch den scdaemon bzw. pcscd nicht (extra Ausnahme in der Config).

    Schließlich wurde ich auf bugs.debian.org/cgi-bin/bugrep… fündig. Offenbar wurden bei Polkit Rules entfernt, die es Usern erlauben, pcscd/Smartcards zu nutzen... am 8. September beim Update wurde /usr/share/polkit-1/rules.d/sssd-pcsc.rules so geändert, dass die Rule nur mehr für Root zieht. Da wurde das File zumindest aktualisert.
    Und heut erst wurde die Änderung durch den Zwangsreboot schlagend...

    Die Lösung war auf jeden Fall folgende:
    Ich hab ein File /etc/polkit-1/rules.d/40-allow-pcscd.rules

    # cat 40-allow-pcscd.rules 
    polkit.addRule(function(action, subject) {
        if (
            subject.isInGroup("plugdev")
            && (
                action.id === "org.debian.pcsc-lite.access_pcsc"
                || action.id === "org.debian.pcsc-lite.access_card"
            )
        ) {
            return polkit.Result.YES;
        }
    
        return polkit.Result.NOT_HANDLED;
    });

    erstellt und meinen User der Gruppe plugdev hinzugefügt. Ab/Anmelden, damit die Gruppenänderung zieht... und schon konnte ich meinen Yubikey wieder für die Authentifikation für ssh-Verbindungen nutzen.

    Aber warum gpg am Yubikey nicht mehr funktioniert... bleibt mir auch ein Rätsel.

  29. #Ubuntu24 verweigerte heute nach einem Reboot die Nutzung meines #Yubikeys.
    Ich konnte mich als mit #pkcs11 nicht mehr an meinen Servern per ssh anmelden.

    Eine hängengebliebene Filesystem-Action eines Remote-Filesystems verhinderte offenbar, dass Linux meinen Laptop nicht schlafen schicken konnte... Totem ließ sich nicht beenden vom Kernel... aber das ist eine andere Geschichte. Jedenfalls schaltete sich mein Laptop nicht ab bis der Akku leer war.

    In einem Anfall seniler Bettflucht hab ich meinen Laptop hergenommen und wollte checken, warum Friendica nur mehr blurred Vorschaubilder anzeigt (Spoiler, das Debuglog eines anderen Services füllte mir die Platte an...) und mein ssh-agent verweigerte das Hinzufügen des Yubikeys. Standhaft.

    Ein Blick ins Journal ergab dann folgende Seltsamkeit:

    Sep 12 04:34:02 AET-1931 pcscd[24807]: 99999999 auth.c:143:IsClientAuthorized() Process 36310 (user: 2000) is NOT authorized for action: access_pcsc
    Sep 12 04:34:02 AET-1931 pcscd[24807]: 00000197 winscard_svc.c:355:ContextThread() Rejected unauthorized PC/SC client

    Ein Restart von pcscd brachte keine Erlösung.
    Ein Reboot übrigens auch nicht.

    Also weitersuchen. Aufgrund der Recherchen einmal

    opensc-tool --list-readers
    No smart card readers found.

    Shice... und was sagt gpg?

    gpg --card-status
    gpg: selecting card failed: Kein passendes Gerät gefunden
    gpg: OpenPGP Karte ist nicht vorhanden: Kein passendes Gerät gefunden

    Das Journal dazu befragt... scdaemon erkennt meine Smartcards, aber pcscd verweigert meinem User den Zugriff.

    Also mal als Root... ja, da liefert opensc-tool meine Smartcards.

    Dann eine noch seltsamere Erkenntnis...
    In tmux ausgeführt, verweigert pcscd die Abfrage mit opensc-tool, in der normalen Bash gibts aber ein Ergebnis... meine Token sind da.

    Dann hab ich meinen SafeNet eToken ausprobiert... der ließ sich wunderbar zum ssh-agent hinzufügen... gut, der nutzt aber auch den scdaemon bzw. pcscd nicht (extra Ausnahme in der Config).

    Schließlich wurde ich auf bugs.debian.org/cgi-bin/bugrep… fündig. Offenbar wurden bei Polkit Rules entfernt, die es Usern erlauben, pcscd/Smartcards zu nutzen... am 8. September beim Update wurde /usr/share/polkit-1/rules.d/sssd-pcsc.rules so geändert, dass die Rule nur mehr für Root zieht. Da wurde das File zumindest aktualisert.
    Und heut erst wurde die Änderung durch den Zwangsreboot schlagend...

    Die Lösung war auf jeden Fall folgende:
    Ich hab ein File /etc/polkit-1/rules.d/40-allow-pcscd.rules

    # cat 40-allow-pcscd.rules 
    polkit.addRule(function(action, subject) {
        if (
            subject.isInGroup("plugdev")
            && (
                action.id === "org.debian.pcsc-lite.access_pcsc"
                || action.id === "org.debian.pcsc-lite.access_card"
            )
        ) {
            return polkit.Result.YES;
        }
    
        return polkit.Result.NOT_HANDLED;
    });

    erstellt und meinen User der Gruppe plugdev hinzugefügt. Ab/Anmelden, damit die Gruppenänderung zieht... und schon konnte ich meinen Yubikey wieder für die Authentifikation für ssh-Verbindungen nutzen.

    Aber warum gpg am Yubikey nicht mehr funktioniert... bleibt mir auch ein Rätsel.

  30. #Ubuntu24 verweigerte heute nach einem Reboot die Nutzung meines #Yubikeys.
    Ich konnte mich als mit #pkcs11 nicht mehr an meinen Servern per ssh anmelden.

    Eine hängengebliebene Filesystem-Action eines Remote-Filesystems verhinderte offenbar, dass Linux meinen Laptop nicht schlafen schicken konnte... Totem ließ sich nicht beenden vom Kernel... aber das ist eine andere Geschichte. Jedenfalls schaltete sich mein Laptop nicht ab bis der Akku leer war.

    In einem Anfall seniler Bettflucht hab ich meinen Laptop hergenommen und wollte checken, warum Friendica nur mehr blurred Vorschaubilder anzeigt (Spoiler, das Debuglog eines anderen Services füllte mir die Platte an...) und mein ssh-agent verweigerte das Hinzufügen des Yubikeys. Standhaft.

    Ein Blick ins Journal ergab dann folgende Seltsamkeit:

    Sep 12 04:34:02 AET-1931 pcscd[24807]: 99999999 auth.c:143:IsClientAuthorized() Process 36310 (user: 2000) is NOT authorized for action: access_pcsc
    Sep 12 04:34:02 AET-1931 pcscd[24807]: 00000197 winscard_svc.c:355:ContextThread() Rejected unauthorized PC/SC client

    Ein Restart von pcscd brachte keine Erlösung.
    Ein Reboot übrigens auch nicht.

    Also weitersuchen. Aufgrund der Recherchen einmal

    opensc-tool --list-readers
    No smart card readers found.

    Shice... und was sagt gpg?

    gpg --card-status
    gpg: selecting card failed: Kein passendes Gerät gefunden
    gpg: OpenPGP Karte ist nicht vorhanden: Kein passendes Gerät gefunden

    Das Journal dazu befragt... scdaemon erkennt meine Smartcards, aber pcscd verweigert meinem User den Zugriff.

    Also mal als Root... ja, da liefert opensc-tool meine Smartcards.

    Dann eine noch seltsamere Erkenntnis...
    In tmux ausgeführt, verweigert pcscd die Abfrage mit opensc-tool, in der normalen Bash gibts aber ein Ergebnis... meine Token sind da.

    Dann hab ich meinen SafeNet eToken ausprobiert... der ließ sich wunderbar zum ssh-agent hinzufügen... gut, der nutzt aber auch den scdaemon bzw. pcscd nicht (extra Ausnahme in der Config).

    Schließlich wurde ich auf bugs.debian.org/cgi-bin/bugrep… fündig. Offenbar wurden bei Polkit Rules entfernt, die es Usern erlauben, pcscd/Smartcards zu nutzen... am 8. September beim Update wurde /usr/share/polkit-1/rules.d/sssd-pcsc.rules so geändert, dass die Rule nur mehr für Root zieht. Da wurde das File zumindest aktualisert.
    Und heut erst wurde die Änderung durch den Zwangsreboot schlagend...

    Die Lösung war auf jeden Fall folgende:
    Ich hab ein File /etc/polkit-1/rules.d/40-allow-pcscd.rules

    # cat 40-allow-pcscd.rules 
    polkit.addRule(function(action, subject) {
        if (
            subject.isInGroup("plugdev")
            && (
                action.id === "org.debian.pcsc-lite.access_pcsc"
                || action.id === "org.debian.pcsc-lite.access_card"
            )
        ) {
            return polkit.Result.YES;
        }
    
        return polkit.Result.NOT_HANDLED;
    });

    erstellt und meinen User der Gruppe plugdev hinzugefügt. Ab/Anmelden, damit die Gruppenänderung zieht... und schon konnte ich meinen Yubikey wieder für die Authentifikation für ssh-Verbindungen nutzen.

    Aber warum gpg am Yubikey nicht mehr funktioniert... bleibt mir auch ein Rätsel.

  31. Saw some post about migrating #authenticator apps... and I realised I never used Google app for example. Because when I started configuring #2FA, I already had #Yubikeys :blobcatpeek2:

    So I naturally downloaded their Yubico Authenticator to use something I could use, without even thinking. And this was/is my first #OTP app I ever used.
    I tried FreeOTP or something similar when it was recommended for some work thing in previous job, but never had a chance to really "feel" that because I changed jobs shortly after.
    And now I thought for the first time that my only experience with OTP is when codes aren't device-locked... :blobcatgiggle:
    And for me it's absolutely natural state, as things should be.

    #Yubikey

  32. Saw some post about migrating #authenticator apps... and I realised I never used Google app for example. Because when I started configuring #2FA, I already had #Yubikeys :blobcatpeek2:

    So I naturally downloaded their Yubico Authenticator to use something I could use, without even thinking. And this was/is my first #OTP app I ever used.
    I tried FreeOTP or something similar when it was recommended for some work thing in previous job, but never had a chance to really "feel" that because I changed jobs shortly after.
    And now I thought for the first time that my only experience with OTP is when codes aren't device-locked... :blobcatgiggle:
    And for me it's absolutely natural state, as things should be.

    #Yubikey

  33. Saw some post about migrating #authenticator apps... and I realised I never used Google app for example. Because when I started configuring #2FA, I already had #Yubikeys :blobcatpeek2:

    So I naturally downloaded their Yubico Authenticator to use something I could use, without even thinking. And this was/is my first #OTP app I ever used.
    I tried FreeOTP or something similar when it was recommended for some work thing in previous job, but never had a chance to really "feel" that because I changed jobs shortly after.
    And now I thought for the first time that my only experience with OTP is when codes aren't device-locked... :blobcatgiggle:
    And for me it's absolutely natural state, as things should be.

    #Yubikey

  34. Saw some post about migrating #authenticator apps... and I realised I never used Google app for example. Because when I started configuring #2FA, I already had #Yubikeys :blobcatpeek2:

    So I naturally downloaded their Yubico Authenticator to use something I could use, without even thinking. And this was/is my first #OTP app I ever used.
    I tried FreeOTP or something similar when it was recommended for some work thing in previous job, but never had a chance to really "feel" that because I changed jobs shortly after.
    And now I thought for the first time that my only experience with OTP is when codes aren't device-locked... :blobcatgiggle:
    And for me it's absolutely natural state, as things should be.

    #Yubikey

  35. Saw some post about migrating #authenticator apps... and I realised I never used Google app for example. Because when I started configuring #2FA, I already had #Yubikeys :blobcatpeek2:

    So I naturally downloaded their Yubico Authenticator to use something I could use, without even thinking. And this was/is my first #OTP app I ever used.
    I tried FreeOTP or something similar when it was recommended for some work thing in previous job, but never had a chance to really "feel" that because I changed jobs shortly after.
    And now I thought for the first time that my only experience with OTP is when codes aren't device-locked... :blobcatgiggle:
    And for me it's absolutely natural state, as things should be.

    #Yubikey

  36. I wonder... Am I the only one who quite frequently accidentally puts the #smartphone with #NFC enabled on #Yubikeys and activates factory-set Yubico OTP when trying to simply put my phone on my desk? :blobcatsweat:
    It happens ever through few layers of paper sheets - often because of this, when I cannot see keys hidden under paper pile. As I remember one time was through thin notebook.

    #Yubikey

  37. I wonder... Am I the only one who quite frequently accidentally puts the #smartphone with #NFC enabled on #Yubikeys and activates factory-set Yubico OTP when trying to simply put my phone on my desk? :blobcatsweat:
    It happens ever through few layers of paper sheets - often because of this, when I cannot see keys hidden under paper pile. As I remember one time was through thin notebook.

    #Yubikey

  38. I wonder... Am I the only one who quite frequently accidentally puts the #smartphone with #NFC enabled on #Yubikeys and activates factory-set Yubico OTP when trying to simply put my phone on my desk? :blobcatsweat:
    It happens ever through few layers of paper sheets - often because of this, when I cannot see keys hidden under paper pile. As I remember one time was through thin notebook.

    #Yubikey

  39. I wonder... Am I the only one who quite frequently accidentally puts the #smartphone with #NFC enabled on #Yubikeys and activates factory-set Yubico OTP when trying to simply put my phone on my desk? :blobcatsweat:
    It happens ever through few layers of paper sheets - often because of this, when I cannot see keys hidden under paper pile. As I remember one time was through thin notebook.

    #Yubikey

  40. I wonder... Am I the only one who quite frequently accidentally puts the #smartphone with #NFC enabled on #Yubikeys and activates factory-set Yubico OTP when trying to simply put my phone on my desk? :blobcatsweat:
    It happens ever through few layers of paper sheets - often because of this, when I cannot see keys hidden under paper pile. As I remember one time was through thin notebook.

    #Yubikey

  41. Oh, look, another thrilling blog post about creating your own offline PKI system with 3 #YubiKeys and a computer that can barely run Tetris! 😂 Because nothing screams "fun weekend project" like locking yourself in an air-gapped bunker just to feel marginally more secure while the rest of us enjoy the cloud, amirite? ☁️🔒
    vincent.bernat.ch/en/blog/2025 #offlinePKI #security #humor #weekendproject #airgapped #HackerNews #ngated

  42. Oh, look, another thrilling blog post about creating your own offline PKI system with 3 #YubiKeys and a computer that can barely run Tetris! 😂 Because nothing screams "fun weekend project" like locking yourself in an air-gapped bunker just to feel marginally more secure while the rest of us enjoy the cloud, amirite? ☁️🔒
    vincent.bernat.ch/en/blog/2025 #offlinePKI #security #humor #weekendproject #airgapped #HackerNews #ngated

  43. Oh, look, another thrilling blog post about creating your own offline PKI system with 3 #YubiKeys and a computer that can barely run Tetris! 😂 Because nothing screams "fun weekend project" like locking yourself in an air-gapped bunker just to feel marginally more secure while the rest of us enjoy the cloud, amirite? ☁️🔒
    vincent.bernat.ch/en/blog/2025 #offlinePKI #security #humor #weekendproject #airgapped #HackerNews #ngated

  44. Oh, look, another thrilling blog post about creating your own offline PKI system with 3 #YubiKeys and a computer that can barely run Tetris! 😂 Because nothing screams "fun weekend project" like locking yourself in an air-gapped bunker just to feel marginally more secure while the rest of us enjoy the cloud, amirite? ☁️🔒
    vincent.bernat.ch/en/blog/2025 #offlinePKI #security #humor #weekendproject #airgapped #HackerNews #ngated

  45. People who use hardware security keys: Storing them in geographically diverse locations is a wise move but makes it impossible to quickly onboard. How do you keep track of where you’ve registered each key? A checklist in a spreadsheet is obvious but cumbersome. Is there a better way? (Yes I use passkeys extensively but for certain services like email, iCloud, and my password manager, a hardware option is desirable if not mandatory.) #YubiKey #YubiKeys #FIDO #FIDO2 #FIDOKey #FIDOKeys #Security

  46. People who use hardware security keys: Storing them in geographically diverse locations is a wise move but makes it impossible to quickly onboard. How do you keep track of where you’ve registered each key? A checklist in a spreadsheet is obvious but cumbersome. Is there a better way? (Yes I use passkeys extensively but for certain services like email, iCloud, and my password manager, a hardware option is desirable if not mandatory.) #YubiKey #YubiKeys #FIDO #FIDO2 #FIDOKey #FIDOKeys #Security

  47. People who use hardware security keys: Storing them in geographically diverse locations is a wise move but makes it impossible to quickly onboard. How do you keep track of where you’ve registered each key? A checklist in a spreadsheet is obvious but cumbersome. Is there a better way? (Yes I use passkeys extensively but for certain services like email, iCloud, and my password manager, a hardware option is desirable if not mandatory.) #YubiKey #YubiKeys #FIDO #FIDO2 #FIDOKey #FIDOKeys #Security

  48. People who use hardware security keys: Storing them in geographically diverse locations is a wise move but makes it impossible to quickly onboard. How do you keep track of where you’ve registered each key? A checklist in a spreadsheet is obvious but cumbersome. Is there a better way? (Yes I use passkeys extensively but for certain services like email, iCloud, and my password manager, a hardware option is desirable if not mandatory.) #YubiKey #YubiKeys #FIDO #FIDO2 #FIDOKey #FIDOKeys #Security

  49. People who use hardware security keys: Storing them in geographically diverse locations is a wise move but makes it impossible to quickly onboard. How do you keep track of where you’ve registered each key? A checklist in a spreadsheet is obvious but cumbersome. Is there a better way? (Yes I use passkeys extensively but for certain services like email, iCloud, and my password manager, a hardware option is desirable if not mandatory.) #YubiKey #YubiKeys #FIDO #FIDO2 #FIDOKey #FIDOKeys #Security

  50. I've written a new blog post (9000 words) taking a moderately deep dive into "Threat Modeling YubiKeys and Passkeys"

    yawnbox.is/blog/threat-modelin

    I greatly welcome feedback as I want to make sure I'm not misrepresenting anything. I want to make it better if it can be improved. I'm happy to be wrong, just please provide details and links!

    also, i need a job! if you like my work, maybe you know of something where i'd be a good fit.

    #infosec #cybersecurity #IAM #FIDO2 #WebAuthn #YubiKey #YubiKeys #passkey #passkeys #GetFediHired

  51. I've written a new blog post (9000 words) taking a moderately deep dive into "Threat Modeling YubiKeys and Passkeys"

    yawnbox.is/blog/threat-modelin

    I greatly welcome feedback as I want to make sure I'm not misrepresenting anything. I want to make it better if it can be improved. I'm happy to be wrong, just please provide details and links!

    also, i need a job! if you like my work, maybe you know of something where i'd be a good fit.

    #infosec #cybersecurity #IAM #FIDO2 #WebAuthn #YubiKey #YubiKeys #passkey #passkeys #GetFediHired

  52. I've written a new blog post (9000 words) taking a moderately deep dive into "Threat Modeling YubiKeys and Passkeys"

    yawnbox.is/blog/threat-modelin

    I greatly welcome feedback as I want to make sure I'm not misrepresenting anything. I want to make it better if it can be improved. I'm happy to be wrong, just please provide details and links!

    also, i need a job! if you like my work, maybe you know of something where i'd be a good fit.

    #infosec #cybersecurity #IAM #FIDO2 #WebAuthn #YubiKey #YubiKeys #passkey #passkeys #GetFediHired

  53. I've written a new blog post (9000 words) taking a moderately deep dive into "Threat Modeling YubiKeys and Passkeys"

    yawnbox.is/blog/threat-modelin

    I greatly welcome feedback as I want to make sure I'm not misrepresenting anything. I want to make it better if it can be improved. I'm happy to be wrong, just please provide details and links!

    also, i need a job! if you like my work, maybe you know of something where i'd be a good fit.

    #infosec #cybersecurity #IAM #FIDO2 #WebAuthn #YubiKey #YubiKeys #passkey #passkeys #GetFediHired

  54. I've written a new blog post (9000 words) taking a moderately deep dive into "Threat Modeling YubiKeys and Passkeys"

    yawnbox.is/blog/threat-modelin

    I greatly welcome feedback as I want to make sure I'm not misrepresenting anything. I want to make it better if it can be improved. I'm happy to be wrong, just please provide details and links!

    also, i need a job! if you like my work, maybe you know of something where i'd be a good fit.

    #infosec #cybersecurity #IAM #FIDO2 #WebAuthn #YubiKey #YubiKeys #passkey #passkeys #GetFediHired