#securitykeys

TechGlimmertechglimmer
2025-12-11

Passwords are yesterday’s defense. 🔐

Hardware security keys using FIDO2/WebAuthn give you phishing resistant logins with a tap, and they work across major services like Google, Microsoft, and many password managers.​

New TechGlimmer guide explains:

How hardware keys work

Why they are stronger than SMS or app codes

What to look for (USB‑C, NFC, platform support) when choosing a key.​

Read more: techglimmer.io/learn-about-har

2025-12-09

Actually, you just significantly reduced my security, Gandi. You should have let the users manage this transition, or at least warn them ahead of time what was going to happen if they didn't.

Replacing unphishable auth (old school U2F is still quite functional!) with phishable auth (email) without user consent is not acceptable.

#Gandi #SecurityKeys #U2F

Gandi is evolving, and so is its security!

Security keys now use a new protocol. Keys registered before September 10, 2019, are no longer compatible and have been deactivated.

Therefore, we have removed your security keys: [redacted] from your account.

To maintain a satisfactory level of security, we have enabled MFA via email for your account.

However, you can re-register them in your administration console, in the ACCOUNT application
2025-12-05

Durch den #CLT2025 Talk zu Passwortlose Logins mit #PassKeys media.ccc.de/v/clt25-188-passw bin ich auf die #Token2 PIN+ #Securitykeys aufmerksam geworden token2.com/shop/category/pin-p
Die DualPort Keys sind wohl sehr nützlich, haben 300 Resident Keys, kommen mit Hülle und kosten nur 26€.
Zur Wasserfestigkeit finde ich leider nichts.
Würde mich über Erfahrungsberichte freuen.
#FIDO2

2025-10-27

X users, time is ticking—re-enroll your 2FA keys by November 10, 2025, or risk getting locked out. Find out how this move is set to tackle rising cyber threats and secure your account for the future!

thedefendopsdiaries.com/mandat

#2fa
#securitykeys
#accountsecurity
#phishingprotection
#cybersecurity2025

2025-06-27

Well, that's something you don't see every day - a still-panelized set of 16 security keys!

I'm told these were part of Google's Titan / Gnubby development process. (Artemis was a daughter of Leto, who was a Titan -- get it?)

I assume they don't have firmware on them yet, but it might be tricky to find out non-invasively.

#SecurityKeys #Gnubby

A 4x4 panelized set of USB-A security keys, in the YubiKey "Nano" size and style, but labeled "ARTEMIS" across in white.
2025-06-21

Security key that's new to me: Thetis Nano-C!

thetis.io/products/thetis-nano

Also news to me, I'm clearly behind: FIDO2 has levels:

fidoalliance.org/certification

This key is FIDO2 L1, and different applications may require different levels. Notably here, L1 is the minimum to get any certification at all, and you can't get L2 unless you have an actual secure hardware element. So with the device at this level, you get the independence of a separate physical object with a dramatically simpler software surface, but I suspect it might be easier to get secrets right off the key with physical possession.

(Note that this is an organic post, not sponsored in any way. Happened upon it in an eBay listing. I never do solicited or compensated endorsements)

#SecurityKeys

A hero image of the Thetis Nano USB-C key. The USBC connector takes up roughly half of the vertical size. And oblong section for grabbing the key is the other half, with the Thetis name and logo. There's a small loop at that height on one side for keychain use.Technical Specifications

Connector: USB-C
NFC Enable: No
Passkey Slots: 200
OATH Slots: 50
Design: Nano Design with Aluminum
Shield
Algorithm: SHA256, AES, HMAC, ECDH,
ECDSAA compatibility table, including a variety of websites such as Google, Facebook, etc. rows, and operating system and browser columns.
X's in Facebook on iOS and Android Chrome, Dropbox for iOS and Android app, Duo for iOS app and Chrome and Android app, Dashlane for all iOS and Android.Large title: Fido/passkey compatible only 

FIDO2 L1 Protect Wide Range Service

Check Your Account FIDO Compatibility before purchase

[A 3x3 grid of logos, including Google, Apple, Microsoft, Adobe, Amazon, Facebook, X, Salesforce, Uber]


Exceptions to Note:

ID Austria: Not supported-requires FIDO2 Level 2 certification.
Windows Hello Login: Only supported on Windows Enterprise with Entra ID.
2025-05-17

GoDaddy makes you pick which security key you want to be prompted for by default, and only allows this key to be presented unless you follow the "try another way" workflow.

What is the purpose / threat model of this? It seems unnecessarily high friction to me, and as far as I know is not done by any other platform.

#SecurityKeys

2025-01-29

Since the last time I logged in fresh, Google has moved "2-step only" (non-passkey) security keys to be the first factor prompted for.

Only after a good key is presented is the user prompted for their password.

You are then prompted to create a passkey "instead", with a "Not now" option.

#SecurityKeys #MFA

2025-01-03

TIL Proton dropped their maximum supported security keys (some time after mid-August 2024) from 8 to 4 keys?! (Notice the tiny "8 out of 4" label, because I had registered the maximum 8 keys)

I suspect my current config will be stable until I need to explicitly delete a key, in which case I won't be able to add a replacement unless I delete five keys. 😡

#MFA #SecurityKeys #FIDO2 #Proton

Proton security settings for security keys, where 7 redacted keys are listed by name, with an eighth not shown, and the maximum described as four, producing a nonsensical label that basically means "you have 8 out of four keys registered"
2024-12-16

@aleidk I replaced “mobile phone account“ with “mobile phone provider account” to be clearer about what I meant.

For banks (in the EU), AFAIK there is a strong reason why they never even mention FIDO2: for a transaction at least, the device where validation is performed must give basic info on the transaction: seller and amount.

Another point: the software support depends on site, browser (e.g., Firefox desktop != Firefox mobile), type of key, physical communication protocol (like USB vs. NFC). I made a lot of tests with various sites and my USB-A and USB-C keys, sometimes using NFC, other times USB. Some combinations don't work, or worked at some point and not later (or worked with Chrome but not Firefox, etc.). This can be quite stressful or even dangerous if this is for an important account and you have no backup plan (⇒ don't). And if the backup options are 1) exploitable in your threat model and 2) not very secure, this obviously reduces or nukes the advantage of using a security key in the first place.

A typical backup option which is not insecure from my POV if well handled is a set of recovery codes, but for this you need to store them very carefully, safely... and not forget how to access them in x years! In these conditions, setting up a new account requires “some work”.

And I say all this despite wishing FIDO2 great success, 'cause SIM swapping attacks in particular are quite scary given how much important stuff still depends on codes sent by SMS. 😐

#FIDO2 #SecurityKeys #authentication #threatModel

Abdelkader Bouiabdelkader_boui
2024-12-15

Nutzt hier jemand Dropbox über den Safari-Browser auf macOS und hat Google Titan Keys? Lassen sich bei euch die Titan Keys als Security Keys im Dropbox-Account hinterlegen? In Safari klappt die Einbindung nicht. Es kommt die Fehlermeldung "Key Not Found". In Edge konnte ich einen von zwei Titan Keys einrichten.

Locking Down Your Digital Life: Why Security Keys Are Your Ultimate Shield youtu.be/W8JoSShkD4c #cybersecurity #securitykeys #yubikey #passkeys #riskmanagement

2024-11-22

TIL the maximum number of security keys I can add to my Apple account is ... six. 😢

Say it ain't so, @rmondello !

#SecurityKeys

2024-11-04

It's been 12 days since I (and a few others) noticed ... and we're still unable to rename security keys within a Google Account.

reddit.com/r/GoogleSupport/com

Renaming keys is essential, to keep them identified and disambiguated.

#Google #SecurityKeys #FIDO2

Google Account settings, "Passkeys and security keys" section. Background (page) lists five security keys (four redacted, one "FIDO2 security key, Created: just now). Foreground is the modal "Manage your key" dialog, with an "Edit your key's name" field label, and "testrename" typed into the field. A black dynamic popup at the bottom of the page background says "Something went wrong. Try again."
2024-02-20

I have just published my next article related to #fido #securitykeys and how they can be managed in the #commandline

blog.tinned-software.net/fido2

2024-02-14

@techlore made a video about my basic security research on the #VisionPro

youtube.com/watch?v=NzuFNFx2_J

for those people who want good security for their #Apple account, and use #SecurityKeys, other people, even Apple (sales reps at the store when I returned mine), recommend creating a new Apple ID and not securing it

aside from the lapse in #security, it also means any apps or media that i've purchased with my main Apple account would have to be repurchased

no?

2024-01-09

Security key vendor I hadn't seen before: "SLING". Appears to be repackaged TrustKey (formerly eWBM) T110 and T120. Interestingly, the hostname (www dot slingsecure dot com) does not currently resolve.

#securitykeys #fido2

Security key in blue-backed bubble pack, slightly fat black USB-A key, with a "T" inside a few circles on the touch surface. "SLING" in caps, "T110" just elow, with the "110" inverted (blue on white)Back of the T110 package. 

www.slingsecure.com
UPC: 809636 790116
Model: eTA110
R-R-eWB-eTA110
Made in KoreaOnly difference from the front bubble photo of the T110 is that 110 is 120, and the connector is USB-C.www.slingsecure.com
UPC: 809636 790109
Model: eTA120
R-R-eWB-eTA120
Made in Korea
2023-11-22

Coinbase has also broken the logic around enforcing the current max 5 security keys - it lets you try to add a 6th, but then fails with an unknown error.

#coinbase #securitykeys

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst