Adaprox has various "finger bots" for those who don't want to build their own: https://www.adaprox.io/
There is also MicroBot: https://microbot.is/push/ I used it for testing smart meters in Norway, so we did not need to run to the lab to trigger events. The best part is that the whole menu is interactive by just one physical button, a great job for a Bluetooth button pusher + Python. It is also capacitive so it work on the phone screen, and YubiKeys (?)
Pressing YubiKeys
71–80 of 241 posts
Re: Pressing YubiKeys
#72Re: Pressing YubiKeys
#73The author must live in some kind of bubble. This may only be true at Big Tech companies or other companies with a atypically strong security focus.
Re: Pressing YubiKeys
#74The final thoughts at the end of the article are amazing: "Why not just press the button?" ... "Don’t you get it? This button BAD, but this button GOOD. Me want to press GOOD button."
Re: Pressing YubiKeys
#75The obvious next step is to plug this into a server and control it through USB over IP. Call it "remote, centrally controlled 2FA" and your manager will love it!
Re: Pressing YubiKeys
#76Rogue trigger of a security token isn't really an issue when using the recommended U2F standard.
U2F uses the domain as part of the challenge-response in U2F so that phishing\spoofing attacks can be defeated.
Re: Pressing YubiKeys
#77Re: Pressing YubiKeys
#78"If you work in tech, you probably have a YubiKey" The author must live in some kind of bubble. This may only be true at Big Tech companies or other companies with a atypically strong security focus.
Re: Pressing YubiKeys
#79A slight aside, but so many of these keys seem to have the touch point / button applying force perpendicular to the direction of insertion, I wonder if there is any long-term potential to cause damage to the USB interface.