Auth needs to be able to be decoupled from phones. With the OnlyKey, I've stored the important TOTP keys as well like my email as well as password for my password manager. Being as 'dumb' as they are, I've had it go through the wash still working fine.
FIDO2 security key company publishes results of internal security audit
21–30 of 64 posts
Re: FIDO2 security key company publishes results of internal security audit
#22Re: FIDO2 security key company publishes results of internal security audit
#23I am probably wrong, but I think Fido2 keys should be ubiquitous. They provide a hardened solution for some security situations, certainly they could be a good 2nd factor or 3rd, and hopefully they could reduce the password madness we have. Yubico appears focused on the enterprise and high end users resulting in higher prices. Solokeys seems more focused on individual users with lower prices. Disclaimer I have two Yu…
Re: FIDO2 security key company publishes results of internal security audit
#24I got a Solokey as part of the Kickstarter and love em. USB-C + NFC in one device. The one thing I'd love out of a security key is the ability to set up a "Twinned Pair". So I can have one key on my keychain that I use everyday and one I keep in my safe in case something happens to the primary. Yes, I know some services support multiple security keys - but setting up two is more work and not all services do support t…
I have two Yubikeys, one in a safe and one on my person. It saved my butt when I lost access to the one on my person for a few days!
Re: FIDO2 security key company publishes results of internal security audit
#25I am probably wrong, but I think Fido2 keys should be ubiquitous. They provide a hardened solution for some security situations, certainly they could be a good 2nd factor or 3rd, and hopefully they could reduce the password madness we have. Yubico appears focused on the enterprise and high end users resulting in higher prices. Solokeys seems more focused on individual users with lower prices. Disclaimer I have two Yu…
Don't get me wrong I love the idea of physical/hardware security; however, isn't the reason it is so effective right now because it is not mainstream?
Re: FIDO2 security key company publishes results of internal security audit
#26Re: FIDO2 security key company publishes results of internal security audit
#27Earlier quoted context omitted.
Don't get me wrong I love the idea of physical/hardware security; however, isn't the reason it is so effective right now because it is not mainstream?
Go on...?
Re: FIDO2 security key company publishes results of internal security audit
#28Re: FIDO2 security key company publishes results of internal security audit
#29Physical hardware seems like a promising replacement for passwords. But is there any real adoption in consumer services right now? The only two services I know that suppport Fido2 are Google and GitHub. Are there any other big services I'm missing here?
Also Dropbox, Salesforce, Gandi, Namecheap, and a couple cryptocurrency exchanges, according to https://www.dongleauth.info.
Re: FIDO2 security key company publishes results of internal security audit
#30Physical hardware seems like a promising replacement for passwords. But is there any real adoption in consumer services right now? The only two services I know that suppport Fido2 are Google and GitHub. Are there any other big services I'm missing here?
Dropbox is also an early adopter.
Plus you have all the u2f that are back compat, including facebook, twitter, aws, gitlab... (I may have confuse some u2f that already moved to webauthn, if so, sorry).
Considering that webauthn was standardized last March and that ios still has no in-app support, that’s a pretty good start, I think.