Earlier quoted context omitted.
If Secure Enclave is as secure as Apple claims it to be, Safari‘s option might actually be the safest one. Of course you can’t use that on anything other than a Mac or iPhone, so in some situations you need another key.
It's a bit more specific than that, no? You can't use Safari's option on anything other than that particular Mac or iPhone. It's my understanding that you can't extract the secret key from the secure enclave.
How to Yubikey
121–130 of 186 posts
Re: How to Yubikey
#122Reminder: Yubico doesn't have a monopoly on security keys. Make sure your software/tutorials support the open-source alternatives like OnlyKey and NitroKey.
do any other keys have feature sets on par with yubikeys? last i checked they were ahead by a mile, the others i looked at were just fido2 keys
Re: How to Yubikey
#123What if I lose this yubikey? This is stupid. My passwords are locked inside of my head.
Re: How to Yubikey
#124Earlier quoted context omitted.
Aren't you always vulnerable in this scenario? If you have your device in your possession, you also likely have your key in your possession in order to use your device.
If your threat profile really includes the possibility of getting hit by a wrench, you can devise a means of destroying the key quickly.
And note that you may die even if you want to reveal; especially if you've setup a system that prevents you from revealing (two person keys, etc).
Re: How to Yubikey
#125Your paranoia is getting out of hand, seriously. 2FA here, OTP there. Idk about you, maybe you do have such sensitive data that you have to double guard everything, I and the usual average guy doesn't. Why do I care? Because this craze has already reached the real world. Amazon requiring 2FA on deliveries. Wtf is wrong with my passport or other document? Nothing. Now I have to be physically present and recite some fu…
My World of Warcraft account had been secured by 2FA 10y earlier than my bank account. The good thing is, the launcher app on _my_ PC got the feature (a few years ago) that I only need to use the actual 2FA fob once every few months, not every time I login. It protects me against the most common case (someone logging in with my account/stealing my account) while not getting in the way at all. Unless someone breaks in…
Re: How to Yubikey
#126The new fangled ed25519 stuff simply didn't work for me.
Re: How to Yubikey
#127Reminder: Yubico doesn't have a monopoly on security keys. Make sure your software/tutorials support the open-source alternatives like OnlyKey and NitroKey.
Hell, even software based implementations which force domain checking would solve 99% of the problem…
Re: How to Yubikey
#128Reminder: Yubico doesn't have a monopoly on security keys. Make sure your software/tutorials support the open-source alternatives like OnlyKey and NitroKey.
From the website:
>The TKey™ is a new kind of USB security key inspired by measured boot and DICE.
>TKey™s design encourages developers to experiment with new security key applications and models in a way that makes adoption easier and less risky forend-users.
>TKey™ is and always will be open source hardware and software. Schematics, PCB design and FPGA design source as well as all software source code can be found on GitHub.
[1]: https://www.tillitis.se/ -- also "tillit" is Swedish for "trust" and "mullvad" is Swedish for "mole" (the animal).
Re: How to Yubikey
#129Earlier quoted context omitted.
do any other keys have feature sets on par with yubikeys? last i checked they were ahead by a mile, the others i looked at were just fido2 keys
If they don't, that's more of a reason to use the OTHERS? You really don't want a monoculture here.
Re: How to Yubikey
#130I like the idea of securitykeys, but having to drop 100€ for a key (since in my opinion you are playing with fire if you don't buy a backup) feels like excessive and then having to worry that I remember to take my securitykey with me everywhere... Yeah, yeah, security vs. convenience is always the issue, but so far I've just selected convenience.