Earlier quoted context omitted.
Can you recommend any cheap USB security keys? I've looked in the past and cost has been prohibitive.
Have you looked into these? https://solokeys.com
TOTP tokens on my wrist with the smartest dumb watch
11–20 of 131 posts
Re: TOTP tokens on my wrist with the smartest dumb watch
#12Cool hack. That said: A security reminder to anyone who is in the target audience here: if you're clever enough to have TOTP 2FA enabled on your Google account, get some cheap USB security keys and enable Advanced Protection, which completely disables non-hardware 2FA. It requires two different tokens (and you should really get one for each computer you have/use, plus at least one offsite backup) because once enabled…
> TOTP is not much better than SMS-based 2FA. It's still vulnerable to phishing, local device malware (that attacks your TOTP in your password manager), etc. It's best to use hardware tokens everywhere that support them, and both Google and GitHub do. (And Google supports a special hardware token only mode which I wish more sites would adopt.) Since this device doesn't actually have network connectivity he might have…
Re: TOTP tokens on my wrist with the smartest dumb watch
#13How accurate does the time have to be for TOTP to work? If the watch drifts a bit, will it no longer work? Compared to your phone which is synced with an NTP server.
Re: TOTP tokens on my wrist with the smartest dumb watch
#14[edit] https://www.crowdsupply.com/oddly-specific-objects/sensor-wa...
Re: TOTP tokens on my wrist with the smartest dumb watch
#15How accurate does the time have to be for TOTP to work? If the watch drifts a bit, will it no longer work? Compared to your phone which is synced with an NTP server.
Re: TOTP tokens on my wrist with the smartest dumb watch
#16Earlier quoted context omitted.
> TOTP is not much better than SMS-based 2FA. It's still vulnerable to phishing, local device malware (that attacks your TOTP in your password manager), etc. It's best to use hardware tokens everywhere that support them, and both Google and GitHub do. (And Google supports a special hardware token only mode which I wish more sites would adopt.) Since this device doesn't actually have network connectivity he might have…
TOTP is really vulnerable to phishing. Hardware keys are the solution.
EDIT: yes, lol, thank you for explaining what phishing is jgrahamc. We didn't know. I get that a lot of Americans and some Germans guard their car keys like an internal organ, but for a lot of people in the world a keychain is something you toss in an insecure place most of the time of the day.
Re: TOTP tokens on my wrist with the smartest dumb watch
#17Earlier quoted context omitted.
TOTP is really vulnerable to phishing. Hardware keys are the solution.
Yeah, sure, but then again a watch on your wrist is harder to take away than a hardware key on your physical keychain that you don't pay attention to. EDIT: yes, lol, thank you for explaining what phishing is jgrahamc. We didn't know. I get that a lot of Americans and some Germans guard their car keys like an internal organ, but for a lot of people in the world a keychain is something you toss in an insecure place mo…
Re: TOTP tokens on my wrist with the smartest dumb watch
#18Earlier quoted context omitted.
Have you looked into these? https://solokeys.com
I was a backer of the V2 and I think my order is now a year overdue. I don't really back things on kickstarter because I don't like to gamble, but this seemed like a sure bet. Turns out it wasn't.
Re: TOTP tokens on my wrist with the smartest dumb watch
#19Cool hack. That said: A security reminder to anyone who is in the target audience here: if you're clever enough to have TOTP 2FA enabled on your Google account, get some cheap USB security keys and enable Advanced Protection, which completely disables non-hardware 2FA. It requires two different tokens (and you should really get one for each computer you have/use, plus at least one offsite backup) because once enabled…
Can you recommend any cheap USB security keys? I've looked in the past and cost has been prohibitive.
If anything under $100 is too much to secure your account, just use SMS 2FA, or disable 2FA entirely.
Re: TOTP tokens on my wrist with the smartest dumb watch
#20Cool hack. That said: A security reminder to anyone who is in the target audience here: if you're clever enough to have TOTP 2FA enabled on your Google account, get some cheap USB security keys and enable Advanced Protection, which completely disables non-hardware 2FA. It requires two different tokens (and you should really get one for each computer you have/use, plus at least one offsite backup) because once enabled…
Can you recommend any cheap USB security keys? I've looked in the past and cost has been prohibitive.
I also have a pair of github-branded yubikeys from a long time ago but I don’t remember what that program was.
> cost has been prohibitive.
A titan is 35 or so, hardly prohibitive. And if you have access to anything important your company ought be glad to get you one or two, or yubis.