Readit News logoReadit News
jaefi commented on Ask HN: What programming jobs are least likely to be disrupted by AI?    · Posted by u/div3rs3
jaefi · a year ago
Anything that requires more than a boilerplate (everything).
jaefi commented on Using FIDO keys   777.tf/blog/2023/12/08/us... · Posted by u/jaefi
throwawayqqq11 · 2 years ago
Your government id card is not widely adopted as method of authentification, i guess. This is where this new pass key approach comes in. My concern is, that this new method might completely replace old fashioned passwords. And once every one is used to have a hardware token, the next step of only accepting or selling government approved devices is a small one. This could could ultimately make anonymity impossible. Because you dont control the hardware or the spec.

Imagine being required to have and use your govID for simply everything, because there is no alternative.

This is not a risk of secure authentification, which passwords can also provide.

$Corps loved to harvest phone numbers as a second factor despite a second fall back email address would be at least as secure as SS7 communication. But phone numbers are tied more strongly to your identity so more valuable for the data brokers.

This is the same thing actually. Tieing identity to something you have and not something you alone know. Something external.

Having a single external dependency for all your identities sounds like a good idea to you? For facists and data brokers it certainly does.

To me, this is an attack on anonymity and i know that i sound paranoid. Lets wait for the enshitening.

jaefi · 2 years ago
You DON’T have to trust any company or government for passwordless authentication. Don’t want to use your phone? Use a hardware key instead. Don’t want to use a hardware key? Use an open source solution like Bitwarden (and it’s not the only one).

At this point, you’re just making shit up about something you don’t understand.

jaefi commented on Using FIDO keys   777.tf/blog/2023/12/08/us... · Posted by u/jaefi
DistractionRect · 2 years ago
That's actually what gives me confidence. All the hardware manufacturing problems almost ensure a v3 will be designed.
jaefi · 2 years ago
I meant more the lack up updates and communication doesn't really paints a bright future for Solokeys.
jaefi commented on Using FIDO keys   777.tf/blog/2023/12/08/us... · Posted by u/jaefi
guerby · 2 years ago
After looking at various keys and their features I chose basic FIDO2 with NFC with no storage or other fancy feature.

Keys with lots of feature have a larger code base and this means more bugs in the long term.

I use my FIDO2 keys for proxmox, ssh ed25519-sk, vaultwarden, nextcloud, GAFAM accounts.

Unfortunately I know of no bank that has adopted FIDO2/webauthn.

Note: Paypal only allows one FIDO2 key AFAIK, so not an option there.

jaefi · 2 years ago
Looking at bank security is probably the saddest landscape around. Most will ask you for a PIN at maximum and then tell you it's not possible to have stronger authentication because of "safety".

I wish there was stronger laws forcing banks to adopt stuff like that.

jaefi commented on Using FIDO keys   777.tf/blog/2023/12/08/us... · Posted by u/jaefi
aidenn0 · 2 years ago
Yubikey 5 can only store 20, which isn't a whole lot better. Are there yet any readily available FIDO devices that can store 100s of resident keys (I have almost 400 logins in bitwarden)?
jaefi · 2 years ago
The new Google Titan keys can store hundreds; sadly not even sure if I can get one here.
jaefi commented on Using FIDO keys   777.tf/blog/2023/12/08/us... · Posted by u/jaefi
spiridow · 2 years ago
My colleague and I recently gave a workshop about security keys where we tried to answer questions like:

* Why should I use a security key?

* What is it used for?

* How can I choose one ?

* What features should I look for?

We did cover FIDO2/Passkeys but also multiple other use cases.

Here are the slides if you're interested: https://tome.one/slides/amiet-pelissier-security-keys-worksh...

jaefi · 2 years ago
Oh that's interesting, thanks for linking it!
jaefi commented on Using FIDO keys   777.tf/blog/2023/12/08/us... · Posted by u/jaefi
DistractionRect · 2 years ago
I have a couple v1 Solokey Somus lying about. Good little devices. Unfortunately the main selling point of upgradeable firmware is moot if they no longer support the old devices and you have to upgrade. At that point it's they're like everyone else. Except they require some setup on some machines, whereas other keys "just work"

I've since replaced them with yubikeys. Yubikeys have a better feature set (at least compared to by v1's) and at this point are fairly mature/stable. V2 is still pitched as alpha quality, and probably will be deprecated with a v3. As much as I want Solokeys to succeed, I just can't recommend them either.

jaefi · 2 years ago
Given how the project is going, not even sure if there will be a V3 at some point.
jaefi commented on Using FIDO keys   777.tf/blog/2023/12/08/us... · Posted by u/jaefi
evanjrowley · 2 years ago
Cool article!

Sorry your SoloKey V2 experience isn't going so well. I have a V1 and it's been surprisingly robust over the past 3 years. For NFC, I can only get it working with my Pixel 7 phone of I remove the thick OtterBox case. Perhaps your issue is also related to your case thickness? Having to remove the case is a hassle, so I am sticking with multipurpose USB-A to USB-C adapters for now.

I've been using YubiKeys for like 10 years, but the 5C model I recently got suddenly stopped working out of nowhere. It only lasted me from October to November of this year. I've been wondering if the brand has had a quality drop-off.

Of the security keys in my possession, the Thetis U2F key has lasted the longest (~5 years) and has had no problems whatsoever. They've since released updated FIDO keys, and so I purchased 2.

Good luck on your hardware MFA journey!

jaefi · 2 years ago
Hey! For the NFC thing, I tried with and without a case and seems the issue remains the same (maybe just a hardware failure). I must say I had more chances with NFC on my USB-C key thought it's still a bit jittery. On the other hand, the Yubikey's NFC works perfectly, even with the case.

Also I didn't knew about Thetis, I'm gonna look into those.

jaefi commented on Using FIDO keys   777.tf/blog/2023/12/08/us... · Posted by u/jaefi
jaefi · 2 years ago
I wrote a small article about security keys. I hope y'all will like it.

u/jaefi

KarmaCake day35June 19, 2021
About
Author at 777.tf
View Original