It is time.

#opsec

Reply to this note

Please Login to reply.

Discussion

awesome! i have the same model 🔥

What are they?

hardware authentication devices

https://www.yubico.com/

So it’s a cold wallet for your passwords?

for mfa. and yes, that's how i see it and use it

...and passkeys

"YubiKey is designed to meet you where you are on your authentication journey by supporting a broad range of authentication protocols, including FIDO U2F, WebAuthn/FIDO2 (passkeys), OTP/TOTP, OpenPGP and Smart Card/PIV."

*typo: ignore the first line*

So just the authenticator for 2FA or does it actually store passwords as well?

it is a mfa hardware authenticator key. it does not store passwords, except for when using the yubikey in secure static password mode where it is recommended the user store only half of a password i.e. the user types the first half, then uses the yubikey to complete the other half.

check out the website for more info 🤙🏻

https://www.yubico.com/products/how-the-yubikey-works/

Any gotchas I should look out for?

how so?

Never set one up before.

i think you'll be good. i'm here to help if not

I should get me one of thems.

they're awesome...even as passkeys are trying to send them the way of the dodo bird.

Yeah I run a vaultwarden instance (I think that does passkeys I know bitwarden does but I forget if vautwarden did). I was wondering if its still useful.

Can be used as 2FA with Bitwarden, but I’m not sure about vaultwarden.

I know it can be a 2fa for vaultwarden. I think the only thing vaultwarden gets rid of is the enterprise features like SSO and a few other things.

did you see the article i posed before about this? if not, are you up for a bit of a technical read that's totally worth it?

I did not and I'm always up for a technical read. Ill look for it.

hang on, i'll find it

just reposted it

Sick ill add that to my rss as well. Looks like a good blog.

it is

What are you knitting?

Security.

I want one. Do they make them smaller?

We will need a mould, and then we can get it made.

I'll have to pick up a few. do thy make them for desktop? Or will I need an adapter for one of these?

They make both USB-A and C models.

Ohhh I see what these are for. Is best place to buy from Yubico?

Only easy place I found was direct. Took two days.

Smart man getting two!

I've got one of these on my keyring. Been using it for years with github, bitwarden, and a few other websites.

I also use TOTP as a fallback and I have an TOTP database and little rust program on an offline computer in case I lose my phone I still have all my TOTP seeds.

I *hate* TXT based 2-factor. My phone provider sometimes gets stuck and TXTs don't arrive for hours, then they come all as a batch. And it's too easy for someone to impersonate my SIM.

Not to mention SMS not being encrypted.

I’m not gonna lie, Apple Passkeys made me think about this lately. This is my first set, so I’m going slow. GitHub, Microsoft, and Google are my trial accounts, since they were on passkeys already.

I just felt this is something better done externally to the device 🤷‍♂️

You can also secure your ssh sessions with them.