Live data from Hacker News

Using FIDO keys

777.tf

1–10 of 65 posts

Re: Using FIDO keys

#3
post #2

I wrote a small article about security keys. I hope y'all will like it.

Cool article!

Sorry your SoloKey V2 experience isn't going so well. I have a V1 and it's been surprisingly robust over the past 3 years. For NFC, I can only get it working with my Pixel 7 phone of I remove the thick OtterBox case. Perhaps your issue is also related to your case thickness? Having to remove the case is a hassle, so I am sticking with multipurpose USB-A to USB-C adapters for now.

I've been using YubiKeys for like 10 years, but the 5C model I recently got suddenly stopped working out of nowhere. It only lasted me from October to November of this year. I've been wondering if the brand has had a quality drop-off.

Of the security keys in my possession, the Thetis U2F key has lasted the longest (~5 years) and has had no problems whatsoever. They've since released updated FIDO keys, and so I purchased 2.

Good luck on your hardware MFA journey!

Re: Using FIDO keys

#4
post #2

I wrote a small article about security keys. I hope y'all will like it.

Cool article! Sorry your SoloKey V2 experience isn't going so well. I have a V1 and it's been surprisingly robust over the past 3 years. For NFC, I can only get it working with my Pixel 7 phone of I remove the thick OtterBox case. Perhaps your issue is also related to your case thickness? Having to remove the case is a hassle, so I am sticking with multipurpose USB-A to USB-C adapters for now. I've been using YubiKey…

Hey! For the NFC thing, I tried with and without a case and seems the issue remains the same (maybe just a hardware failure). I must say I had more chances with NFC on my USB-C key thought it's still a bit jittery. On the other hand, the Yubikey's NFC works perfectly, even with the case.

Also I didn't knew about Thetis, I'm gonna look into those.

Re: Using FIDO keys

#5
I have a couple v1 Solokey Somus lying about. Good little devices. Unfortunately the main selling point of upgradeable firmware is moot if they no longer support the old devices and you have to upgrade. At that point it's they're like everyone else. Except they require some setup on some machines, whereas other keys "just work"

I've since replaced them with yubikeys. Yubikeys have a better feature set (at least compared to by v1's) and at this point are fairly mature/stable. V2 is still pitched as alpha quality, and probably will be deprecated with a v3. As much as I want Solokeys to succeed, I just can't recommend them either.

Re: Using FIDO keys

#6
I use an old Google Titan key, not the bluetooth model but the regular one, as my backup (it was my primary) and a Yubikey 5 for my primary. I like the peace of mind that they give me that no one can steal my password and login to my important accounts, but I found that certain providers only allow a single 2FA to be used, with no backup, so I don't feel good using them there (AWS, what the F?) and also I find that not a lot of services support 2FA in the form of keys, they all want to use TOTP or SMS generally, so I only can really use these for my Fastmail and Bitwarden and a few other accounts, but for my bank or my health insurance, they do not support FIDO keys. I also can't use them on any government sites! I know passkeys are going to rule the world soon, but I don't like the idea that my phone and a 3rd party have access to this 2nd factor; I prefer a separate key for this purpose.

Re: Using FIDO keys

#7
post #6

I use an old Google Titan key, not the bluetooth model but the regular one, as my backup (it was my primary) and a Yubikey 5 for my primary. I like the peace of mind that they give me that no one can steal my password and login to my important accounts, but I found that certain providers only allow a single 2FA to be used, with no backup, so I don't feel good using them there (AWS, what the F?) and also I find that n…

AWS IAM supports multiple keys now! I think this was a blocker for using hardware keys on AWS for a bunch of organizations.

https://aws.amazon.com/about-aws/whats-new/2022/11/aws-ident...

Re: Using FIDO keys

#9

I have a couple v1 Solokey Somus lying about. Good little devices. Unfortunately the main selling point of upgradeable firmware is moot if they no longer support the old devices and you have to upgrade. At that point it's they're like everyone else. Except they require some setup on some machines, whereas other keys "just work" I've since replaced them with yubikeys. Yubikeys have a better feature set (at least compa…

Given how the project is going, not even sure if there will be a V3 at some point.

Re: Using FIDO keys

#10
My colleague and I recently gave a workshop about security keys where we tried to answer questions like:

* Why should I use a security key?

* What is it used for?

* How can I choose one ?

* What features should I look for?

We did cover FIDO2/Passkeys but also multiple other use cases.

Here are the slides if you're interested: https://tome.one/slides/amiet-pelissier-security-keys-worksh...

Post reply on HN