mastodon.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
The original server operated by the Mastodon gGmbH non-profit

Administered by:

Server stats:

347K
active users

#solokeys

0 posts0 participants0 posts today
Continued thread

Besides the #Nitrokey FIDO2, I also already have a Nitrokey U2F & a Solo Somu from #SoloKeys, so I wasn't too keen on paying 50€ + shipping for a new Nitrokey 3A Mini – a product I wouldn't need if my old key's firmware had been updated.

Instead, I bought a 🇨🇭 Token2 PIN+ Dual R3 whose hardware and firmware is also open-source and which costs only 25€ + shipping: token2.eu/shop/product/pin-dua #T2F2

The only downside is that #Token2 manufacture their products outside Europe (Nitrokeys are made in 🇩🇪).

www.token2.euTOKEN2 Sàrl is a Swiss cybersecurity company specialized in the area of multifactor authentication. We are a FIDO Alliance member.FIDO2 USB Key, U2F USB Key, Cheap Yubico alternative, FIDO2, fido alliance certified security keys Replace your mobile authenticator with secure hardware OTP token! Easily programmed via NFC. Designed to use with Google, Facebook, Dropbox, GitHub, Wordpress, Office 365, Azure MFA etc.

fediverso, #ayuda de nuevo por favor. me podeis recomendar / comentar sobre llaves #hardware #FIDO2 ?
Conozco #yubikey pero preferiria una alternative #FOSS he estado mirando #nitrokey nitrokey.com #solokeys solokeys.eu y #thetis thetis.io la que mas me llama la atencion es la nitrokey

y una duda global que me choca mucho... el hecho de que el contacto USB, este desprotegido, en pelotas... no es un gran riesgo de un rapido deterioro!? si tengo pensado tener la llave en un llavero (hola? es una puta llave! normal, no?) o en el bolsillo sin llavero.. va a estar en continuo contacto / restriego con otras cosas que lleve en el bolsillo y por lo tanto se podria dañar, no? o el contacto usb de todas estas llaves son indestructibles...

se agradece boost!

Backed #solokeys and #solokeysv2 and no idea what's going on anymore?
It seems that the creators/founders completely abandoned the project at this point.
I created a small thread on their Discussions on their repo and I'd like to see what would happen if we bring enough attention to it.

So please, share this as much as possible, since they don't want to communicate, let's force them.

See the thread there:
https://github.com/solokeys/solo2-cli/discussions/117

#security #scam #boostme :boost_ok:

GitHubStatus of the project · solokeys solo2-cli · Discussion #117As you may have noticed, the last commit on this repository was on 2023/17/01, well-over a full year ago. The Solo1 repository is even worse as the last commit was on 2022/03/23 which will be almos...

Update on #solokeys and #solokeysv2

Months after sending an e-mail asking where the project was at since
absolutely no updates whatsoever, it still is ignored.

I can safely say that Solokeys is a dead project. Buy Yubikey, it'll save you headaches.

Finally got my solokey V2s. I'm pretty happy with it, but I did find 1 issue with it. It seems like, if I connect a key to an account using my computer, my phone will not be able to connect to it using NFC?

I can still connect to it using my USB-A to USB-C adapter, but I was wondering if there was something else I could do?

#FIDO2 - the superior Multi Factor #Authentication Framework
media.ccc.de/v/camp2023-57174-
(50min) by @cy

Great overview/intro talk about #2FA using #WebAuthN, hardware security tokens, #TOTP and #passkeys.

Furthermore: why FIDO2 does have some advantages compared to passkeys when #security is more important than convenience. Passkeys leaks your private key to the #cloud provider.

#MFA #YubiKey #Solokeys #NitroKey

/cc @frank @keno3003

Replied in thread

@frank @keno3003 Du meinst Resident Keys: duo.com/labs/tech-notes/reside

AFAIK brauchst du die nur für #Passkeys aber nicht für Standard #FIDO2. Mein #Solokeys hat 50 slots für Resident Keys, manche #Yubikeys nur 25.

Du kannst aber unendlich viele FIDO2 Services mit einem Token betreiben. Noch ein Vorteil von FIDO2 HW-Token.

HTH

Duo SecurityResident Keys and the future of WebAuthn/FIDO2Read our review of the current status of WebAuthn as well as an explanation of how resident keys are enabling username-less logins.

@garritfra related to your "I won't buy a YubiKey" from garrit.xyz/posts/2023-03-21-i-

First: #YubiKey is only one company who sells #FIDO2 compatible devices. So I'd recommend to use "FIDO2" as the open standard instead of product lines of companies. I own a #SoloKeys and it's also providing FIDO2 services.

Second: my main argument for owning and using a FIDO2 USB device is that this is the only method that protects against #phishing which is one of the most prominent threats these days. #security

garrit.xyzI won't buy a YubiKey