mastodontech.de ist einer von vielen unabhängigen Mastodon-Servern, mit dem du dich im Fediverse beteiligen kannst.
Offen für alle (über 16) und bereitgestellt von Markus'Blog

Serverstatistik:

1,5 Tsd.
aktive Profile

#securitykey

0 Beiträge0 Beteiligte0 Beiträge heute
xyhhx 🔻 (plz hire me)<p>i *still* don't understand how this onlykey works. i've kinda figured out how to generate subkeys (you have to have $GNUPGHOME point to a valid keyring that has a public key on which you want to create a subkey for, but use `--homedir` to point to a new directory for onlykey to put the new keyring with the subkey), but now it won't generate keys except for the uid i used to use? </p><p><a href="https://nso.group/tags/onlykey" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>onlykey</span></a> <a href="https://nso.group/tags/hardwareKey" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>hardwareKey</span></a> <a href="https://nso.group/tags/securityKey" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>securityKey</span></a> <a href="https://nso.group/tags/pgp" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>pgp</span></a> <a href="https://nso.group/tags/gpg" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>gpg</span></a></p>
Nitrokey<p>⏰ While 2024 is reaching the finish line, we‘d like to take a moment to thank everyone who is supporting us on our mission to secure the digital life. 🛡 <br>We‘re truly grateful for having such loyal customers. 🙏 </p><p>We wish you happy holidays! 🎄 <br>May 2025 be the year we all wish for! 💪 <br>Stay secure! 🙂 </p><p><a href="https://social.nitrokey.com/tags/nitrokey" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>nitrokey</span></a> <a href="https://social.nitrokey.com/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cybersecurity</span></a> <a href="https://social.nitrokey.com/tags/staysecure" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>staysecure</span></a> <a href="https://social.nitrokey.com/tags/nitrokeypro" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>nitrokeypro</span></a> <a href="https://social.nitrokey.com/tags/opensource" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>opensource</span></a> <a href="https://social.nitrokey.com/tags/internetsecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>internetsecurity</span></a> <a href="https://social.nitrokey.com/tags/securitykey" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>securitykey</span></a> <a href="https://social.nitrokey.com/tags/usbkey" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>usbkey</span></a> <a href="https://social.nitrokey.com/tags/secureyourdigitallife" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>secureyourdigitallife</span></a></p>
Colan Schwartz<p>This is unfortunate because I received a pair of these recently that I've been meaning to take out of the package. I guess they won't be issuing recalls?</p><p><a href="https://arstechnica.com/security/2024/09/yubikeys-are-vulnerable-to-cloning-attacks-thanks-to-newly-discovered-side-channel/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">arstechnica.com/security/2024/</span><span class="invisible">09/yubikeys-are-vulnerable-to-cloning-attacks-thanks-to-newly-discovered-side-channel/</span></a></p><p><a href="https://mastodon.social/tags/securitykey" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>securitykey</span></a> <a href="https://mastodon.social/tags/sidechannel" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>sidechannel</span></a> <a href="https://mastodon.social/tags/yubikey" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>yubikey</span></a> <a href="https://mastodon.social/tags/yubikeys" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>yubikeys</span></a> <a href="https://mastodon.social/tags/hardwaretokens" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>hardwaretokens</span></a> <a href="https://mastodon.social/tags/hardwaretoken" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>hardwaretoken</span></a> <a href="https://mastodon.social/tags/cryptography" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cryptography</span></a> <a href="https://mastodon.social/tags/credentials" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>credentials</span></a> <a href="https://mastodon.social/tags/fido" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>fido</span></a></p>
Jef Kazimer😶‍🌫️<p>I don't know who needs to hear this, but put an AirTag on that key ring of FIDO2 security keys you have.</p><p><a href="https://infosec.exchange/tags/passkey" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>passkey</span></a> <a href="https://infosec.exchange/tags/fido2" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>fido2</span></a> <a href="https://infosec.exchange/tags/securitykey" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>securitykey</span></a></p>
nemo™ 🇺🇦<p>🔒 Secure your online accounts with SoloKeys! 🔑<br>Open-source security keys built with Trussed®.<br>Works with Google, Facebook, Twitter &amp; more.<br>Get yours now: </p><p><a href="https://solokeys.com/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">solokeys.com/</span><span class="invisible"></span></a></p><p><a href="https://mas.to/tags/SoloKeys" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SoloKeys</span></a> <a href="https://mas.to/tags/SecurityKey" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SecurityKey</span></a> <a href="https://mas.to/tags/TwoFactorAuth" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TwoFactorAuth</span></a> <a href="https://mas.to/tags/FIDO2" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>FIDO2</span></a> <a href="https://mas.to/tags/OpenSource" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenSource</span></a></p>
🧿🪬🍄🌈🎮💻🚲🥓🎃💀🏴🛻🇺🇸<p>Does anyone know of a bank that lets you use a Fido2 security key to authenticate?</p><p>My bank only allows SMS based 2FA, so my fiat can all be stolen by any employee of my phone company at any time.</p><p><a href="https://mastodon.social/tags/2fa" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>2fa</span></a> <a href="https://mastodon.social/tags/security" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>security</span></a> <a href="https://mastodon.social/tags/fido2" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>fido2</span></a> <a href="https://mastodon.social/tags/securityKey" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>securityKey</span></a> <a href="https://mastodon.social/tags/yubikey" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>yubikey</span></a> <a href="https://mastodon.social/tags/passkey" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>passkey</span></a> <a href="https://mastodon.social/tags/bank" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>bank</span></a> <a href="https://mastodon.social/tags/fido" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>fido</span></a> <a href="https://mastodon.social/tags/webauthn" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>webauthn</span></a> <a href="https://mastodon.social/tags/auth" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>auth</span></a> <a href="https://mastodon.social/tags/authentication" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>authentication</span></a></p>
🧿🪬🍄🌈🎮💻🚲🥓🎃💀🏴🛻🇺🇸<p>PassKeys seem like a bad idea. Google backs them up to the cloud, so if your Google account is compromised then all your private keys are compromised. I don't see how that's an improvement over password+2FA at all.</p><p>Now security keys I get; keep the private key on an airgapped device. That's good. Hell I even keep my 2FA-OTP salts on a YubiKey.</p><p><a href="https://mastodon.social/tags/passkeys" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>passkeys</span></a> <a href="https://mastodon.social/tags/fido2" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>fido2</span></a> <a href="https://mastodon.social/tags/webauthn" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>webauthn</span></a> <a href="https://mastodon.social/tags/yubikey" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>yubikey</span></a> <a href="https://mastodon.social/tags/2fa" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>2fa</span></a> <a href="https://mastodon.social/tags/otp" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>otp</span></a> <a href="https://mastodon.social/tags/authentication" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>authentication</span></a> <a href="https://mastodon.social/tags/cryptography" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cryptography</span></a> <a href="https://mastodon.social/tags/security" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>security</span></a> <a href="https://mastodon.social/tags/passwords" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>passwords</span></a> <a href="https://mastodon.social/tags/passkey" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>passkey</span></a> <a href="https://mastodon.social/tags/password" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>password</span></a> <a href="https://mastodon.social/tags/securityKey" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>securityKey</span></a> <a href="https://mastodon.social/tags/google" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>google</span></a></p>
Michael :donor:<p>When implementing <a href="https://infosec.exchange/tags/WebAuthn" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>WebAuthn</span></a> on an Identity Provider's side. Where exactly should one draw the line between <a href="https://infosec.exchange/tags/SecurityKey" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SecurityKey</span></a> and <a href="https://infosec.exchange/tags/Passkey" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Passkey</span></a>? I see that most platforms make a distinction between those. Can anyone link me some article or blog post on this topic? If I were to implement security key and passkey support on a provider that does not yet support any WebAuthn, should I go down the same route?</p><p>My current assumption is that during passkey registration you'd set "residentKey = required" and "userVerification = required", whereas for a security key you'd set "residentKey = discouraged" and "userVerification = preferred".</p><p>Also, I'm assuming that a security key can also function as a form of <a href="https://infosec.exchange/tags/passwordless" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>passwordless</span></a> multi-factor authentication if UV was true during registration AND authentication. Obviously without the neat part of Passkeys where you don't have to manually enter the username.</p><p><a href="https://infosec.exchange/tags/IAM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IAM</span></a> <a href="https://infosec.exchange/tags/Authentication" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Authentication</span></a></p>
Doug Webb<p>Just ordered a hardware security token.</p><p>Will this improve my security, privacy, coonvenience?</p><p>I'll let you know.</p><p><a href="https://mastodon.xyz/tags/2fa" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>2fa</span></a> <a href="https://mastodon.xyz/tags/mfa" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>mfa</span></a> <a href="https://mastodon.xyz/tags/security" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>security</span></a> <a href="https://mastodon.xyz/tags/securitykey" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>securitykey</span></a></p>
lina<p>Heyyy I'm thinking about buying a security key, probably for only using it with keepassxc, can you guys recommend something solid, that's not overly expensive for a student?<br>I don't wanna /have money for 50eur security key<br>Also with USB-A port<br>There are few with open source hardware which I like but still expensive 30eur, idk what's Sooo expensive on a key like that(I get it custom hardware but still) </p><p><a href="https://uwu.social/tags/security" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>security</span></a> <a href="https://uwu.social/tags/passwordmanager" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>passwordmanager</span></a> <a href="https://uwu.social/tags/password" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>password</span></a> <a href="https://uwu.social/tags/securitykeys" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>securitykeys</span></a> <br><a href="https://uwu.social/tags/yubikey" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>yubikey</span></a> <a href="https://uwu.social/tags/keepassxc" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>keepassxc</span></a> <a href="https://uwu.social/tags/securitykey" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>securitykey</span></a></p>
Matthew Miller :donor:<p>Who here likes hardware-backed end-to-end message encryption, in the browser? Have I got a fun toy for you!</p><p><a href="https://sneakernetsend.com" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">sneakernetsend.com</span><span class="invisible"></span></a></p><p>When I first discovered WebAuthn in 2019 I imagined it being used for something like this, but never imagined something like the prf extension enabling true E2EE like this. Everything happens in the browser; there's no server used in any of this because to me that defeated the purpose. I also challenged myself to make a decent UX on top of this because what good is strong encryption if it's not usable?</p><p>For best results make sure you're using Chrome 116 and a recent FIDO2 security key.</p><p>(I'm also trying to figure out how things get noticed on Hacker News, so if you participate over there here's the Show HN, upvotes appreciated: <a href="https://news.ycombinator.com/item?id=37148972" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">news.ycombinator.com/item?id=3</span><span class="invisible">7148972</span></a>)</p><p><a href="https://infosec.exchange/tags/webauthn" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>webauthn</span></a> <a href="https://infosec.exchange/tags/fido2" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>fido2</span></a> <a href="https://infosec.exchange/tags/securitykey" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>securitykey</span></a> <a href="https://infosec.exchange/tags/e2ee" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>e2ee</span></a> <a href="https://infosec.exchange/tags/chrome" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>chrome</span></a></p>
Tinned-Software<p>For decades, users have authenticated on systems with usernames and passwords. This method of authentication has not changed since the beginning of the Internet. As the Internet became a more hostile place and threats emerged,&nbsp;...</p><p><a href="https://blog.tinned-software.net/secure-authentication-and-how-it-changed-over-time/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">blog.tinned-software.net/secur</span><span class="invisible">e-authentication-and-how-it-changed-over-time/</span></a></p><p><a href="https://infosec.exchange/tags/security" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>security</span></a> <a href="https://infosec.exchange/tags/securitykey" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>securitykey</span></a> <a href="https://infosec.exchange/tags/securitykeys" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>securitykeys</span></a> <a href="https://infosec.exchange/tags/fido" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>fido</span></a> <a href="https://infosec.exchange/tags/fido2" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>fido2</span></a> <a href="https://infosec.exchange/tags/totp" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>totp</span></a> <a href="https://infosec.exchange/tags/passkey" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>passkey</span></a></p>
EINGFOAN :donor:<p>updated <a href="https://infosec.exchange/tags/fido2" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>fido2</span></a> <a href="https://infosec.exchange/tags/fido" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>fido</span></a> <a href="https://infosec.exchange/tags/securitykey" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>securitykey</span></a> <a href="https://infosec.exchange/tags/comparison" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>comparison</span></a> draft Version 0.8 </p><p><a href="https://infosec.exchange/tags/yubikey" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>yubikey</span></a> <a href="https://infosec.exchange/tags/nitrokey" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>nitrokey</span></a> <a href="https://infosec.exchange/tags/gotrust" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>gotrust</span></a> <a href="https://infosec.exchange/tags/feitian" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>feitian</span></a> <a href="https://infosec.exchange/tags/solokey" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>solokey</span></a> <a href="https://infosec.exchange/tags/titan" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>titan</span></a> <a href="https://infosec.exchange/tags/google" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>google</span></a><br><a href="https://infosec.exchange/tags/mfa" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>mfa</span></a> <a href="https://infosec.exchange/tags/u2f" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>u2f</span></a></p><p><span class="h-card"><a href="https://infosec.exchange/@Fr333k" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>Fr333k</span></a></span> <span class="h-card"><a href="https://chaos.social/@matthegap" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>matthegap</span></a></span> <span class="h-card"><a href="https://infosec.exchange/@shellsharks" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>shellsharks</span></a></span> <span class="h-card"><a href="https://infosec.exchange/@FritzAdalis" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>FritzAdalis</span></a></span> <br><span class="h-card"><a href="https://social.heise.de/@heisec" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>heisec</span></a></span></p><p>If updates are needed Post a reply here</p><p>Credits to</p><p><a href="https://medium.com/webauthnworks/sorting-fido-ctap-webauthn-terminology-7d32067c0b01&amp;sa=D&amp;source=editors&amp;ust=1686248837634831&amp;usg=AOvVaw1RNctynoDjZdGOtR_n3KPm" rel="nofollow noopener" target="_blank"><span class="invisible">https://</span><span class="ellipsis">medium.com/webauthnworks/sorti</span><span class="invisible">ng-fido-ctap-webauthn-terminology-7d32067c0b01&amp;sa=D&amp;source=editors&amp;ust=1686248837634831&amp;usg=AOvVaw1RNctynoDjZdGOtR_n3KPm</span></a></p><p><a href="https://fidoalliance.org/specifications/&amp;sa=D&amp;source=editors&amp;ust=1686248837635017&amp;usg=AOvVaw1j45hHJTnxzwWfT7VRfWK6" rel="nofollow noopener" target="_blank"><span class="invisible">https://</span><span class="ellipsis">fidoalliance.org/specification</span><span class="invisible">s/&amp;sa=D&amp;source=editors&amp;ust=1686248837635017&amp;usg=AOvVaw1j45hHJTnxzwWfT7VRfWK6</span></a></p><p><a href="https://doubleoctopus.com/blog/standards-regulations/your-complete-guide-to-fido-fast-identity-online/&amp;sa=D&amp;source=editors&amp;ust=1686248837635116&amp;usg=AOvVaw3wIncGqheQ1koX9LV9-KED" rel="nofollow noopener" target="_blank"><span class="invisible">https://</span><span class="ellipsis">doubleoctopus.com/blog/standar</span><span class="invisible">ds-regulations/your-complete-guide-to-fido-fast-identity-online/&amp;sa=D&amp;source=editors&amp;ust=1686248837635116&amp;usg=AOvVaw3wIncGqheQ1koX9LV9-KED</span></a></p>