Adaprox has various "finger bots" for those who don't want to build their own: https://www.adaprox.io/
I like the concept but the price is steep IMO. $90 for two actuators in the starter kit then $40 for each additional module. I wonder if one could design a similar solution without requiring a bridge. Although of course given the power consumption adding WiFi on the actuators might not be a great idea.
Pressing YubiKeys
101–110 of 241 posts
Re: Pressing YubiKeys
#102Re: Pressing YubiKeys
#103This is gold.
Re: Pressing YubiKeys
#104Congratulations, you've defeated the purpose of having a YubiKey
I know... layers of unlikelihood.. but I'd probably opt for a physical "good button" gapped from my computer as sort of a closed electrical extension of my finger.
Re: Pressing YubiKeys
#105Earlier quoted context omitted.
Considering many services only allow one YubiKey or only one TOTP authenticator ... I might actually need a short term solution like this to beat the 2FA on those services. Otherwise what happens if I lose my key on the road? The 2FA services that allow >1 YubiKey are good, I can have a backup key locked up some place and use them as intended.
You use the backup keys the service gave you when you enabled 2FA.
Supporting multiple keys is a better solution.
Re: Pressing YubiKeys
#106Earlier quoted context omitted.
There are these RSA-brand tokens that show a new TOTP number every few minutes. Occasionally people find an unsecured webcam pointed at one of those somewhere on the internet...
This was a crazy idea I had one day. I'm glad to see that other people have taken the liberty of executing my crazy ideas so that I don't have to.
Re: Pressing YubiKeys
#1071. Plug the yubikey into the monitor
2. Use an extension cord (as they did)
3. Switch back to an otp app (eg Google authenticator or Duo)
4. Credit to conk [1] or agl [2]: extend the conductivity via conductive foil or other material, connect to ground to simulate touch
Ways you can improve convenience while reducing security:
1. This!
2. Disable 2fa (credit to another commenter)
If 2fa is required by your company, circumventing it by eliminating the security benefit should be severely reprimanded.
Why not build a different shitty robot?
Re: Pressing YubiKeys
#108Earlier quoted context omitted.
I remember a story about how our (third party) security operations center doesn’t allow phones on the floor, but most of its customers use Duo Push. So there is a table in the middle of the floor with all the 2FA phones bolted to it.
I don't understand the threats, risk, or solution here.
Re: Pressing YubiKeys
#109Earlier quoted context omitted.
Considering many services only allow one YubiKey or only one TOTP authenticator ... I might actually need a short term solution like this to beat the 2FA on those services. Otherwise what happens if I lose my key on the road? The 2FA services that allow >1 YubiKey are good, I can have a backup key locked up some place and use them as intended.
Looking at you, AWS.