#token2

2026-01-26

I wonder, are there any working SSH clients on iOS that can handle ed255519_sk keys?

(That’s the variant where you have a public and private key part however the private key links to a residential key on an external FIDO2 security token. You plug in the token or use NFC, enter the pin and confirm with a touch)

#ssh #fido2 #token2 #iOS #ed25519

2026-01-26

I am working on the upcoming security key reviews, including a review of Token2's biometric key, Token2 PIN+Bio3, for a future video.

I know many of you view biometrics as a convenience (or a privacy risk), I want to give Token2 praise for the Bio3.

For users with tremors, Parkinson’s, or cerebral palsy, typing a 20+ character passphrase without a typo can be a physical barrier to security.

A fingerprint sensor isn't lazy, for many it is the only accessible way to be secure.

#Token2 #Accessibility #Security #FIDO2 #Privacy #TerminalTilt #GNULinux #GNU #Linux #FOSS #OpenSource

A close up of the Token2 Bio3 hardware key held in fingers, showing the central fingerprint scanner and dual USB connectors.
2026-01-23

To contrast Paypal with Cloudflare, this is how you do it correctly.

I was able to enroll all three of my hardware keys ( @nitrokey , @yubico , and Token2) without issue. No one key limits and no being forced into software backups.

When a platform actually respects FIDO2 as a standard, you can have true hardware redundancy.

Of course, I will mention all of this in my upcoming security key series.

#CyberSecurity #FIDO2 #Nitrokey #YubiKey #Token2 #Hardening #TerminalTilt #Cloudflare #Privacy #Security

A screenshot of the Cloudflare "Authentication" settings page. At the top, a green banner confirms "Two-Factor Authentication is Enabled." The "Security Key Authentication" section is also enabled and displays a table with three registered keys: a Nitrokey 3A NFC, a YubiKey 5C NFC, and Token2 PIN+ 3.3, all enrolled on January 23, 2026. The page also shows sections for mobile app and email authentication, along with a button to regenerate backup codes.
2026-01-23

Is it 2026 or 2006? I just went to harden my PayPal account with my new review units.

Turns out, PayPal still only supports one physical security key. No backups allowed. If you want redundancy, they force you back to TOTP apps or (worse) SMS.

#CyberSecurity #FIDO2 #Yubico #Nitrokey #Privacy #Security #TerminalTilt #FinTechFail #Token2 #Banking #Money

A screenshot of the PayPal "Manage 2-step verification" settings page. It shows 2 step verification is ON, with a "YubiKey 5C NFC" listed as the only primary device. Under the "Your backups" section, only a "Third-party code generator" authenticator app is listed, with no option to add additional backup security keys.
2026-01-15

@pink @nitrokey @yubico

UPDATE #2: The Trifecta is Complete!

I’m thrilled to announce that Token2 is joining the upcoming security series!

I am aligning the Token2 review with their core mission: The death of legacy TOTP.

While many users still rely on codes, Token2 is pushing for a 100% phishing resistant future. We will be focusing exclusively on their Open Source, publicly audited FIDO2 stack. This is a massive win for the #FOSS community. Hardware that is both auditable and explicitly designed to move us past insecure, legacy protocols.

The Comparison is now set:

Yubico: The Industry Giant (Closed Source).

Nitrokey: The Open Hardware Veteran.

Token2: The Audited Open FIDO2 Specialist.

Thank you for the boosts! :tux:

#FOSS #CyberSecurity #Token2 #Yubico #NitroKey #Linux #TechReview #Transparency #TerminalTilt

2026-01-12

Finally finished the #Framework expansion card design for the #Token2 FIDO2 security key.

blog.tinned-software.net/frame

0xKaishakunin0xKaishakunin
2026-01-07

Oh wie schön, die Deutsche Telekom bietet beim Login gleich das Hinzufügen eines an.

Leider ist mein Gerät nicht für Passkeys geeignet, ich kann also weder einen , oder via oder ausrollen.

Da muss man sich in der Implementierung schon richtig Mühe geben, um Hardware-Passkeys auszuschließen.

2026-01-07

When setting up a new hardware key, this feels very insecure. I’m entering the new PIN for it into my browser of all things… What is the recommended way to set a PIN on a #YubiKey and #Token2 using a Mac or Linux machine?

0xKaishakunin0xKaishakunin
2025-12-26

Pünktlich zum habe ich mein erweitert um
.

Ich zeige wie man sich an Servern einloggen kann mittels Device Bound à la , , etc.

Damit liegt der geheime Schlüssel im Passkey-Token und kann nicht ohne weiteres ausgelesen werden.

Außerdem zeige ich noch wie man einen 2. externen OpenSSH-Server nur für die Hardwaretoken konfiguriert.

Viel Spaß am Gerät

cryptomancer.de/posts/20251225

JohaFreuJohaFreu
2025-12-22

are everywhere nowadays

I myself switch to passkeys for any supported service. Have a look here if your services are supported: passkeys.io/who-supports-passk

Understanding why they're more secure and why they are able to be used in so many different shapes is not as easy.

Computerphile just released a greate video about the technology and the authentic flow:
youtube.com/watch?v=xYfiOnufBSk

0xKaishakunin0xKaishakunin
2025-12-07

Ich habe eine kurze bebilderte Anleitung geschrieben wie man mit und Schlüssel direkt auf wie oder erstellt

cryptomancer.de/posts/20251207

Uckermark MacGyver :nonazi:maxheadroom@hub.uckermark.social
2025-12-06

Upgraded from iPhone 12 Pro Max to an iPhone 17. What I do like is the USB-C port. Now my #Token2 #Passkeys fit directly into the phone (yes, would have worked via NFC too, but that always felt a little quirky). Briefly enabled Apple Intelligence. What a complete trainwreck. Deinstalled after 5 minutes again.

2025-12-05

Durch den #CLT2025 Talk zu Passwortlose Logins mit #PassKeys media.ccc.de/v/clt25-188-passw bin ich auf die #Token2 PIN+ #Securitykeys aufmerksam geworden token2.com/shop/category/pin-p
Die DualPort Keys sind wohl sehr nützlich, haben 300 Resident Keys, kommen mit Hülle und kosten nur 26€.
Zur Wasserfestigkeit finde ich leider nichts.
Würde mich über Erfahrungsberichte freuen.
#FIDO2

2025-12-01

Has anyone tested (intentional or not) whether the #token2 PIN+ Dual Release3.3 is water proof?

Jesus Michał "Le Sigh" 🏔 (he)mgorny@treehouse.systems
2025-11-12

Switching from #Nitrokey Pro 2 with rsa2048 key to #Token2 with ed25519 key means switching from rebasing <2 commits a second to an almost instant rebases.

#Gentoo #git #OpenPGP

nocci [cyberpunk'd]nocci@punk.cyber77.de
2025-10-27

mist... hab den Pin meines #Token2 Sticks vergessen und sicherheitshalber auch nicht aufgeschrieben ​:awesome:​

Zum Glück hab ich aber fast bei jedem Account, wo ich sonst noch mit
#Fido2 angemeldet bin noch zwei weitere Sticks aktiv.

​:ablobsmile:​

2025-09-18

@EricAlper
I have so much time for cheap [more] ethical diamonds.
zeeman.com/nl-nl/campagnes/dia
I wonder how small a NFC FIDO2 2FA chip could be shrunk for a necklace? Would look natty.
token2.com/shop/product/t2f2-p
#diamond #diamonds #token2 #zeeman #jewellery #art #infosec

2025-07-24

Just got my Token2 miniOTP-3-i in the mail. Quite a nice device for people who don’t want to store a particular OTP seed on their phone/pc.

It’s programmed via NFC, with an Android or iOS App: the App will read the QRcode during registration and push («burn») the OTP seed onto the miniOTP card. You can also manually input the seed into the App.
The card can store only one OTP seed.

The display is easy to read, the card is really small and barely thicker than a credit card.

Despite the nice user experience so far, I am really disappointed about the refresh of the code: when the OTP expires, you have absolutely no way to know. The device will not refresh the 6 digits code, you have to turn off and on again the card to refresh the OTP. The default setting turns off the display after 15 seconds, so you can’t have an OTP older than ~ 45 seconds (assuming you press the button in the second before the current OTP expires). As most TOTP verifiers will accept the N-1 OTP it’s not a very big deal. But if your are in a more stringent context where only the current OTP is valid, don’t buy this token.

#TOTP #token2 #miniOTP #MFA #2FA

a Token2 miniOTP-3-i card laying on a keyboard for scale (and to brag about my BÉPO keyboard).
The card is way smaller than a credit card. It’s white and brand-less. On the left a tiny NFC logo is printed, the display is on the top right and the on/off button is on the botton right.
Pixelcode 🇺🇦pixelcode@social.tchncs.de
2025-03-23

I didn't buy that Token2 model because of its NFC capability and USB-C connector, but because it's the cheapest #FIDO2 token supporting Ed25519-SK. I did try out using it with my #Fairphone 3 running /e/OS with #MicroG, and it worked fine.

The silicon case I ordered along with the #Token2 key is unfortunately a bit too thick and thereby prevents the key's USB-C connector from being inserted properly into the FP3 if it's wearing its rubber case as well, which makes NFC a bit tricky too.

The packaging of the Token2 PIN+ Dual R3 is red and decorated with a couple security icons as illustrations in the background. Under see-through plastic resides the security key with a USB-C connector on the left and a USB-A connector on the right.

The key itself is black and decorated with the same illustrations of keys, locks and password stars. The serial number written in text form and as a QR code is blacked out for secrecy.

The actual name of the key is a bit ambiguous, because the main label in the middle reads just “PIN+ R3”, while the label in the top left reads “T2F2-NFC-Dual” and then “PIN+ R3” after a line-break.

As their motto, Token2 have apparently chosen “Security is easy” (which is true for their product! 😉).

The description text reads: “The PIN+ security key series enforces strong PIN complexity rules at the firmware level to ensure maximum security.”

Besides the FIDO logo, there are notes indicating that the product was designed in Switzerland and that only keyrings at most 2 mm thick should be used.The Token2 key wearing a white silicon case with caps that protect the USB-A and USB-C connectors and that are attached to the rest of the case with a silicon hinge. The case itself has a metal keyring.

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst