Live data from Hacker News

How Chrome OS, Termux, YubiKey and Duo Mobile make for great usable security

blog.lessonslearned.org

41–50 of 179 posts

Re: How Chrome OS, Termux, YubiKey and Duo Mobile make for great usable security

#41

Earlier quoted context omitted.

Yeah, this is a no go for me. I don't use anything by Google at all. How can a security conscious person talk about privacy and security on a Google device? They are listening, filming and tracking every single thing you do near that device.

That ( "They are listening, filming and tracking every single thing you do near that device" ) is a claim you're going to have to substantiate. Don't spread such rumours unless you can back them up.

Indeed, how dare they suggest that Google would track! They would never do such a thing!

Re: How Chrome OS, Termux, YubiKey and Duo Mobile make for great usable security

#43

Earlier quoted context omitted.

That ( "They are listening, filming and tracking every single thing you do near that device" ) is a claim you're going to have to substantiate. Don't spread such rumours unless you can back them up.

Indeed, how dare they suggest that Google would track! They would never do such a thing!

If the claim being made was that they track your usage of their products, that would have been a reasonable response. But the claim being made is that they continuously monitor you through the webcam and microphone. That is extremely bold and, may I say, complete tinfoil nuttery.

Re: How Chrome OS, Termux, YubiKey and Duo Mobile make for great usable security

#44

Earlier quoted context omitted.

That ( "They are listening, filming and tracking every single thing you do near that device" ) is a claim you're going to have to substantiate. Don't spread such rumours unless you can back them up.

Indeed, how dare they suggest that Google would track! They would never do such a thing!

He's not suggesting they are tracking you through their ad network as you go to websites that use them.

He's suggesting they are secretly filming you, logging your keystrokes, and rerouting your mic audio. That is a very bold claim that should be backed up or retracted.

Re: How Chrome OS, Termux, YubiKey and Duo Mobile make for great usable security

#46
post #34

Regarding the TOTP app, I generally prefer FreeOTP to Google Authenticator/Duo/Authy, etc. It might not provide push codes, but at least the implementation is Open Source and the binaries come from a trusted source.

What is push code?

Re: How Chrome OS, Termux, YubiKey and Duo Mobile make for great usable security

#47
post #46
post #34

Regarding the TOTP app, I generally prefer FreeOTP to Google Authenticator/Duo/Authy, etc. It might not provide push codes, but at least the implementation is Open Source and the binaries come from a trusted source.

What is push code?

I meant a push notification to accept/decline login (so without code in fact).

I've seen Google Authenticator do this (for Google accounts), or the Blizzard Authenticator. I would guess that Duo has a product for this.

Re: How Chrome OS, Termux, YubiKey and Duo Mobile make for great usable security

#48
post #26

What does this achieve? How does this stop anyone compelling you to do your fancy setup?

Whether or not a government can compel you to download and reinstall data to your laptop is a much trickier legal problem than whether they can ask you to show them what is on it currently (in the US they almost certainly can request that at the borders). It also adds to the hassle factor for the border crossing agent. If you are walking through customs/border entry with a in box, factory default chromebook in your checked baggage, changes the legal conversation.

Even if you aren't worried about state level inspection, this setup allows you to put the laptop in your checked baggage and not worry that your data has been intercepted by criminal enterprises in the case of rerouted bags or theft. This is a big boon for many business travelers as they are more worried about IP protection than privacy from governmental interlopers.

Re: How Chrome OS, Termux, YubiKey and Duo Mobile make for great usable security

#49
> When things get completely borked (which in two weeks of heavy use only happened a couple of times for me)

how are people willing to live with this? I would be furious if I had to lose all my state and (for all intents and purposes) restart my machine multiple times in two weeks.

And if this "borking" happens right before or during a presentation (the author was writing about using this setup for giving talks on), this would be very embarassing for me and extremely annoying for the audience.

A work/presentaion machine has to be rock solid for me. No compromises, no workarounds and most certainly no "completely borked". Just pure solid.

Re: How Chrome OS, Termux, YubiKey and Duo Mobile make for great usable security

#50
post #47
post #46

Earlier quoted context omitted.

What is push code?

I meant a push notification to accept/decline login (so without code in fact). I've seen Google Authenticator do this (for Google accounts), or the Blizzard Authenticator. I would guess that Duo has a product for this.

Then it's separate feature from TOTP. It's not a real 2fa because it works like service>duo>user where duo can accept anything for you.
Post reply on HN