jacqueline@chaos.social
jacqueline@chaos.social

do you have a personal, hardware 2fa key? e.g. yubikey or similar

|
Embed
Progress spinner
gsuberland@chaos.social
gsuberland@chaos.social

@jacqueline lol at option 4

|
Embed
Progress spinner
kkarhan@infosec.space
kkarhan@infosec.space

@jacqueline does my brain count?

Cuz that I can effectively deny access to!

|
Embed
Progress spinner
jacqueline@chaos.social
jacqueline@chaos.social

@gsuberland i'm tired of these people, graham.

|
Embed
Progress spinner
indrora@social.sdf.org
indrora@social.sdf.org

@jacqueline yes and I index them: u2f.garden

|
Embed
Progress spinner
gsuberland@chaos.social
gsuberland@chaos.social

@jacqueline mood

|
Embed
Progress spinner
jacqueline@chaos.social
jacqueline@chaos.social

@kkarhan i think that comes under "i'm a pedant / other"

|
Embed
Progress spinner
jacqueline@chaos.social
jacqueline@chaos.social

@indrora nice one dude, that's a really cool project!

|
Embed
Progress spinner
indrora@social.sdf.org
indrora@social.sdf.org

@jacqueline Thanks!

I need to update the data with the YK5 and some 2FA cards the buttcoin community found.

|
Embed
Progress spinner
jacqueline@chaos.social
jacqueline@chaos.social

i've got three, but i'm somewhat ashamed to admit that they're all just stolen from google

|
Embed
Progress spinner
kkarhan@infosec.space
kkarhan@infosec.space

@jacqueline I'd rather consider it under "no", because usng a proper password manager and having unique, secure credentials should do it.

  • I think it's more important to be able to commit Asset Denial and be able to prevent attackers from gaining credentials and heing able to lock them out as soon as someonebsuspects that to happen.
|
Embed
Progress spinner
jacqueline@chaos.social
jacqueline@chaos.social

@kkarhan the other nice thing about the password manager approach is that it doesn't lose effectiveness when encountering the 90% of websites that don't support 2fa tokens.

|
Embed
Progress spinner
ecn@mastodon.social
ecn@mastodon.social

@jacqueline yes, two!

one of them I use for FIDO2 authentication, the other one I use as a smart card / pseudo HSM for storing code signing keys for my iOS apps. I documented how to do it on my blog: ianspence.com/blog/2023-07/app

|
Embed
Progress spinner
traumaphoenix@chaos.social
traumaphoenix@chaos.social

@jacqueline i have three of them

one on a keychain, one in a PD Tech Pouch, one in a drawer because it's a micro and it can't seem to find a system to call its home 🦋

|
Embed
Progress spinner
badrihippo@fosstodon.org
badrihippo@fosstodon.org

@jacqueline no but i want to

|
Embed
Progress spinner
otaviocc
otaviocc

@crossingthethreshold it’s a new M.b feature @manton released recently.

|
Embed
Progress spinner
In reply to
otaviocc
otaviocc

@otaviocc @manton why is my reply in a completely wrong thread? It was supposed to be in a thread in @Mtt’s timeline.

|
Embed
Progress spinner
crossingthethreshold
crossingthethreshold

@otaviocc @manton I missed this one.

|
Embed
Progress spinner
owent@mastodon.social
owent@mastodon.social

@jacqueline i've got two but I can't remember what accounts are tied to the second one and i don't want to dispose of it. please send help

|
Embed
Progress spinner
Mtt
Mtt

@crossingthethreshold I think you’ve got the answer by now, but let me know if not.

|
Embed
Progress spinner
Mtt
Mtt

@otaviocc @manton Same for me. Odd.

|
Embed
Progress spinner
manton
manton

@otaviocc @Mtt There is some bug with Mastodon replies where the wires get crossed somehow. I'll fix this thread.

|
Embed
Progress spinner
kkarhan@infosec.space
kkarhan@infosec.space

@jacqueline also good password managers support #TOTP & #HOTP for #2FA and can even backup and restore these since they are deterministic PRNGs that require an attacker the initial code and initialization time & date within a quite narrow window.

Tho my personal favorite in terms of 2FA is demanding the person logging in to decrypt a PGP-encrypted message to retrieve a confirmation PIN

  • But very, very few sites support that and sadly no password manager that I know of integrates PGP beyond allowing to store private and public keys...

The big advantage of all good password managers is that they allow trivial backups and restores so having an (encrypted!) backup offsite is super fast and easy to do.

  • Also lets face it: Even the biggest "Galaxy Brainchair Chads" I know can't fit 100+ unique, 128-digit passwords in their memory... They have that preoccupied with more important skills...
|
Embed
Progress spinner
crossingthethreshold
crossingthethreshold

@Mtt Yes thank you, but thanks for checking in.

|
Embed
Progress spinner
gnomon@mastodon.social
gnomon@mastodon.social

@jacqueline YubiKeys @tychotithonus , who lives in Alaska with 10,000 security keys, is an outlier adn should not have been counted

|
Embed
Progress spinner
mcc@mastodon.social
mcc@mastodon.social

@jacqueline gotta admit tho this is one of those polls that makes me worry "how anonymous are Mastodon polls, I mean really"

|
Embed
Progress spinner
kevin@mastodon.km6g.us
kevin@mastodon.km6g.us

@jacqueline Two for each of us in the house.

|
Embed
Progress spinner
Natanael_L@mastodon.social
Natanael_L@mastodon.social

@jacqueline not to be confused with "I'm a pendant", where you're someone else's small decorated yubikey on a necklace

|
Embed
Progress spinner
gkrnours@mastodon.gamedev.place
gkrnours@mastodon.gamedev.place

@mcc @jacqueline we should standardize giving a security token to all new employees alongside the usual teesh and totebag. Token2 have a NFC only token in card format that cost 10 bucks

|
Embed
Progress spinner
taivlam@better.boston
taivlam@better.boston

@jacqueline Yes, I have YubiKeys for KeePassXC and SoloKeys 2 for all other U2F/WebAuth/passkeys. I'm trying to figure out how to acquire Nitrokey 3 series devices, but it looks like I'll need to travel to Europe/Germany in the future if I want to avoid paying +50€ for shipping.

|
Embed
Progress spinner