#FIDO2

2026-01-10

@shye hi, does #OpenCloud natively supports #FIDO2?
File encryption is also not perfect?
github.com/orgs/opencloud-eu/d

post factual truthpft@infosec.exchange
2026-01-09

Pitfalls:

  1. When passing -O verify-required to ssh-keygen, you have to disable SSH authentication agent, e.g., using IdentityAgent none in your SSH config. This is a known bug.
  2. If you are using custom key files (without id_ prefix), you need to explicitly define path to key file, e.g. using IdentityFile in the config.

#ssh #yubikey #fido2

post factual truthpft@infosec.exchange
2026-01-09

I settled for non-resident keys. If anyone wants them, they have to torture me twice: once to get the FIDO PIN, and once to get the password to decrypt my hard disk, where the private keys reside.

#threatmodeling #ssh #fido2

2026-01-08

If you ever mess up a `git commit --gpg-sign`, for example, because you connected the wrong FIDO key or none at all, you can find your old commit message under `.git/COMMIT_EDITMSG` before trying to commit again.

I'm a little embarrassed that I didn't realize this until this morning...

#git #fido #fido2

Heyo! My Laptop now requires one of my #FIDO2 keys in addition to my 20 char random password for creating a session.
Setting this up with pam was quite easy. Although I just wanted to try this out, I might let it stay in the config, as it doesn't hurt in any way. I carry one of my keys with me any way.

#linux #security

post factual truthpft@infosec.exchange
2026-01-06

I need your wisdom:

SSH keys on Yubikey:

  • Discoverable/Resident, or
  • Non-Discoverable/Non-Resident

I really appreciate it, if you could also explain the rationale behind your choice.

Thanks.

#yubikey #ssh #fido2

K@rsten :verified_gay:karsbehr@m.k-behrens.de
2026-01-04

Weiß jemand, ob und wie #YunoHost mit #Fido2 bzw. #Passkey funktioniert?

2025-12-29

I login maybe once a year on my domain registrar's website (Gandi). Something has changed in both Firefox/Chromium since last time, because neither of them accepted any of my Yubikeys anymore: it prompted for a PIN, and I don't remember setting one! (I set one on the OpenPGP application, but that PIN is not accepted for FIDO2).

Temporarily disabling FIDO2 allowed the login to succeed as documented here: support.yubico.com/s/article/U support.yubico.com/s/article/E
Note that this does *not* reset FIDO2 (Which IIUC would delete the FIDO U2F key too).
In that case IIUC it uses FIDO U2F instead of FIDO2 with a PIN. Although this seems like a bug, why doesn't the browser offer me the option of using U2F when I reject providing a FIDO2 PIN? Clearly all this worked fine several years ago when I initially registered the Yubikeys.
#FIDO2 #Yubikey #U2F

0xKaishakunin0xKaishakunin
2025-12-26

Pünktlich zum habe ich mein erweitert um
.

Ich zeige wie man sich an Servern einloggen kann mittels Device Bound à la , , etc.

Damit liegt der geheime Schlüssel im Passkey-Token und kann nicht ohne weiteres ausgelesen werden.

Außerdem zeige ich noch wie man einen 2. externen OpenSSH-Server nur für die Hardwaretoken konfiguriert.

Viel Spaß am Gerät

cryptomancer.de/posts/20251225

KipJayChou :debian: :docker:admin@mstdn.feddit.social
2025-12-25

termius上还可以将fido2作为keychain
突然想起来大一上学期买了一个TrustKey T120
试着配置突然想起来自己忘记了PIN
去官网找到了reset方法和管理软件
PDF:trustkey.jp/manual/biomanager_
Download:trustkeysolutions.com/en/sub/s

ok重置好pin🔒和指纹🫆了

#trustkey #pin #fido2 #termius #t120 #pin #fingerprint #ssh

实物图TrustKeyManager.pkgtermius使用trustkey链接到hetzner
Der Entgegner (Aka Ratatöskr)dr_jo_mue@troet.cafe
2025-12-23

ich finde, Internetdienste bei denen ein Schaden entstehen kann (Kommunikation, Finanzen, Waren, Dienstleister) sollten IMMER Hauptschlüssel und physische Passkeys anbieten.

Es kann im Zeitalter von Big Data doch nicht sein, dass man mich zur Passwortwiederherstellung nach dem Geburtsnamen meines ersten Autos/Meerschweinchens/Mutter fragt! Bei Schantal vom Nagelstudio steht das alles vollständig auf Facebook!

#fido2 #passkey #windowshello

JohaFreuJohaFreu
2025-12-22

are everywhere nowadays

I myself switch to passkeys for any supported service. Have a look here if your services are supported: passkeys.io/who-supports-passk

Understanding why they're more secure and why they are able to be used in so many different shapes is not as easy.

Computerphile just released a greate video about the technology and the authentic flow:
youtube.com/watch?v=xYfiOnufBSk

🔮 oracle of dylphi :crumb_dancing: 🇬🇾kalviter@hol.ogra.ph
2025-12-19

Is this something #fido2 on a physical key device would solve? Maybe you mail your customers two keys (a spare and a regular) and have them register both? If one key ever gets lost, the person could contact you for a replacement or buy their own?

I actually looked at the
NCSC guidance for this and was confused at how much they harped on the "ooooh, but people might not like if they have to pay for their own keys, and normally you wouldn't provide these keys for free!" If that's such a major flaw in the use of these hardware keys... why don't services build the cost of providing them in? weird

2025-12-19

This week in #FDroid (TWIF) is live since yesterday:

* #EU #DMA for you and me
* @mimi89999 gives us a reason to activate #NFC #Passkeys #FIDO2
* get the app phone manufacturers hate: #CircleToSearch
* #PeerTube is ready for creators
* #QUIK #SMS got a new appid, did you switch yet?
+ 19 new apps
& 160 updates
- 2 app archived

Touch that special place: f-droid.org/2025/12/18/twif.ht

Varbin :arctic_fox: ​:gay_furr: -> FUKS@39c3varbin@infosec.exchange
2025-12-17

RE: infosec.exchange/@firstyear/11

I have to wholeheartedly agree.

While I do like passkeys, I do like Webauthn & CTAP – the user experience sucks. On my new Android phone I would like to just login again - most of my passkeys are stored on my Yubikey.

Yet most apps randomly do or do not allow me to use it. Sometimes they want to force the password manager. For logging into my Microsoft mail account I was only allowed to select my password manager, although I only have registered my Yubikey. After log in (with password+TOTP) it started the registration flow to store a passkey in my password manager twice.

The only app that did it right is Discord: It asks of you want to use a password manager, the system native implantation (Google, I guess?) or a hardware key for registration and login. Yet I have no idea why this dialogue is not offered by the OS itself.

#Passkey #webauthn #fido2

JohaFreuJohaFreu
2025-12-12

@thoralf

Kann deine Einschätzung 100% verstehen. Ich habe mich für die Option Vpn only entschieden, da die Apps den letzten Stand cachen.
Geräte mit Addin (Notebook) ist in meinem Fall immer mit über Vpn mit meinem Exit Node verbunden. Dadurch habe ich weitere Features wie Web Filter und meine heimische Firewall.

Generell habe ich folgende Ideen:
- Nutzung von -Stick/
- Zero Trust Tunnel mit Access-Filter

Gib gerne ein Update wie du dich entschieden hast.

TechGlimmertechglimmer
2025-12-11

Passwords are yesterday’s defense. 🔐

Hardware security keys using FIDO2/WebAuthn give you phishing resistant logins with a tap, and they work across major services like Google, Microsoft, and many password managers.​

New TechGlimmer guide explains:

How hardware keys work

Why they are stronger than SMS or app codes

What to look for (USB‑C, NFC, platform support) when choosing a key.​

Read more: techglimmer.io/learn-about-har

Network is reliablenetwork_is_reliable
2025-12-08

Wow! I've just discovered that it's possible to use Secure Element as in GrapheneOS via hw-fido2-provider [1] (btw, thank you @S1m) in Vanadium even without any external token. Successfully added my Pixel smartphone as second factor device to my addy.io account. It works finally!

1. codeberg.org/s1m/hw-fido2-prov

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst