#SecurityKey

👀 I’m part of the 0.5% Twitter’s users that use a #SecurityKey for 2FA. Do we know how much people are using this feature in #mastodon ? From: @SpyBlog https://mastodon.social/@SpyBlog/109884411127070890 [Originally posted: 2023-02-18 07:20 UTC]

🇵🇾 Snafu 🐦:linux: 🇺🇦snafu@digitalcourage.social
2025-11-30

Nachdem die Nitrokey 3A Mini offenbar so billig produziert sind, dass mir gestern einer beim simplen Abziehen von einem etwas festeren USB Port in seine Einzelteile zerfallen ist, habe ich beschlossen, auch den anderen einzumotten und komplett zurück zu Yubikey zu wechseln. Die Dinger sind unkaputtbar und auch IP68 zertifiziert. Nutze ich schon seit >15 Jahren ohne jegliche Probleme.

An sich mag ich den Open Source- und Transparenz-Gedanken, unterstütze das auch aktiv, aber wenn die physische Qualität dermaßen unterirdisch ist wie beim Nitrokey 3A Mini (die anderen kann ich nicht beurteilen), dann hilft mir das auch nicht. So ein Security Key ist einigermaßen zentral, der darf nicht einfach so zerfallen bei normaler Nutzung.

#Yubikey #Nitrokey #SecurityKey #Security #FIDO2

2025-11-20

Joost van Dijk from @yubico tells us about #OpenSSH combined with the #FIDO standard at the @nluug #najaarsconferentie. This info applies on any FIDO #securitykey, not just #yubikey.

#opensourceconference #Linuxconference #conference #conferentie #NLUUG #nluug25nj #hardwarekey

Joost van Dijk presenting in front of a slide about hardware-protecting SSH keys.
Francesco Yoshi Gobbo :linux:frayoshi@qoto.org
2025-08-01

Hello Hello!
#SecuX Tech, a Taiwanese business that produces security devices, sent me a security key, the PUFido Clife Key to unbox, and since I was there, I also make a #tutorial and an explanation of what it is.

youtube.com/watch?v=JLNijRxZZV
#PUF #securityKey #unboxing #cyberSecurity

xyhhx 🔻xyhhx@nso.group
2025-05-05

i *still* don't understand how this onlykey works. i've kinda figured out how to generate subkeys (you have to have $GNUPGHOME point to a valid keyring that has a public key on which you want to create a subkey for, but use `--homedir` to point to a new directory for onlykey to put the new keyring with the subkey), but now it won't generate keys except for the uid i used to use?

#onlykey #hardwareKey #securityKey #pgp #gpg

2025-04-02

Hat jemensch schon einmal das Login der Schweizer Behörden (AGOV-Login, siehe agov.admin.ch/de) mit einem Nitrokey 3 getestet und kann etwas zur Kompatibilität sagen?

Geht das oder braucht es "zwingend" einen Schlüssel von Yubico oder Token2 (beide mit L2-Zertifizierung)?

Solo2-Schlüssel gehen jedenfalls nicht und die sind wohl eh EOL. Ich möchte gerne einen Schlüssel mit einer Open-Source-Firmware benutzen.

Nachtrag 1: Der NitroKey 3C geht definitiv nicht. Token2 hingegen schon.

Nachtrag 2: Offensichtlich wird der NitroKey 3C bald eine L2-Zertifizierung erhalten, siehe nitrokey.com/blog/2025/nitroke

@nitrokey #nitrokey #agov #yubikey #schweiz #OpenSource #securitykey

2024-12-24

⏰ While 2024 is reaching the finish line, we‘d like to take a moment to thank everyone who is supporting us on our mission to secure the digital life. 🛡
We‘re truly grateful for having such loyal customers. 🙏

We wish you happy holidays! 🎄
May 2025 be the year we all wish for! 💪
Stay secure! 🙂

#nitrokey #cybersecurity #staysecure #nitrokeypro #opensource #internetsecurity #securitykey #usbkey #secureyourdigitallife

Colan Schwartzcolanschwartz
2024-09-06

This is unfortunate because I received a pair of these recently that I've been meaning to take out of the package. I guess they won't be issuing recalls?

arstechnica.com/security/2024/

Jef Kazimer😶‍🌫️JefTek@infosec.exchange
2024-06-26

I don't know who needs to hear this, but put an AirTag on that key ring of FIDO2 security keys you have.

#passkey #fido2 #securitykey

:awesome:🐦‍🔥nemo™🐦‍⬛ 🇺🇦🍉nemo@mas.to
2024-06-04

🔒 Secure your online accounts with SoloKeys! 🔑
Open-source security keys built with Trussed®.
Works with Google, Facebook, Twitter & more.
Get yours now:

solokeys.com/

#SoloKeys #SecurityKey #TwoFactorAuth #FIDO2 #OpenSource

🧿🪬🍄🌈🎮💻🚲🥓🎃💀🏴🛻🇺🇸schizanon
2024-05-10

Does anyone know of a bank that lets you use a Fido2 security key to authenticate?

My bank only allows SMS based 2FA, so my fiat can all be stolen by any employee of my phone company at any time.

🧿🪬🍄🌈🎮💻🚲🥓🎃💀🏴🛻🇺🇸schizanon
2024-05-03

PassKeys seem like a bad idea. Google backs them up to the cloud, so if your Google account is compromised then all your private keys are compromised. I don't see how that's an improvement over password+2FA at all.

Now security keys I get; keep the private key on an airgapped device. That's good. Hell I even keep my 2FA-OTP salts on a YubiKey.

2024-04-05

Sometimes I just take a moment and watch my SoloKey v2 as its little green light fades in and out, signaling its readiness to protect me online at a moment's notice.
#SoloKey #SoloKeys #SoloKeysV2 #2FA #FIDO #FIDO2 #WebAuthn #SecurityKey

2024-02-21
2024-02-16

The desktop app was the sole reason I used Authy. Not providing an export option sucks. 2FAS is good, but then I didn’t have my phone, and I needed to login to sites that do not accept security keys. FYI - You must have access to your mobile device/2FAS app to use the browser extension.

2023-12-13

When implementing #WebAuthn on an Identity Provider's side. Where exactly should one draw the line between #SecurityKey and #Passkey? I see that most platforms make a distinction between those. Can anyone link me some article or blog post on this topic? If I were to implement security key and passkey support on a provider that does not yet support any WebAuthn, should I go down the same route?

My current assumption is that during passkey registration you'd set "residentKey = required" and "userVerification = required", whereas for a security key you'd set "residentKey = discouraged" and "userVerification = preferred".

Also, I'm assuming that a security key can also function as a form of #passwordless multi-factor authentication if UV was true during registration AND authentication. Obviously without the neat part of Passkeys where you don't have to manually enter the username.

#IAM #Authentication

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst