social.anoxinon.de ist einer von vielen unabhängigen Mastodon-Servern, mit dem du dich im Fediverse beteiligen kannst.
Die offizielle Mastodon Instanz des Vereins Anoxinon e.V.

Serverstatistik:

1,1 Tsd.
aktive Profile

#fido

0 Beiträge0 Beteiligte0 Beiträge heute

New vulnerability with compliments of #Yubikey : "Yubico’s open source pam-u2f software package implements a Pluggable Authentication Module (PAM) that can be deployed to support authentication using a YubiKey or other #FIDO compliant authenticators on macOS or Linux. This software package has an issue which allows for an authentication bypass in some configurations. An attacker would require the ability to access the system as an unprivileged user." yubico.com/support/security-ad

YubicoYSA 2025 01Security Advisory YSA-2025-01 – Partial Authentication Bypass in pam-u2f Software Package Published Date: 2025-01-14Tracking IDs: YSA-2025-01CVE: CVE-2025-23013CVSS Severity: 7.3 Summary Yubico’s open source pam-u2f software package implements a Pluggable Authentication Module (PAM) that can be deployed to support authentication using a YubiKey or other FIDO compliant authenticators on macOS or Linux. This software package has […]
Antwortete im Thread

@TechConnectify Thank you so much for this video. I just watched it and it rings *every* bell. Mastodon is the only social network where I'm "active", apart from that I use #RSS feeds that I picked very well. I try to use my own brain.
It was such a pleasure to listen to you, especially in times like these. Thank you once more.
(But I miss good, ancient #FIDO-net, I must admit)

People who use hardware security keys: Storing them in geographically diverse locations is a wise move but makes it impossible to quickly onboard. How do you keep track of where you’ve registered each key? A checklist in a spreadsheet is obvious but cumbersome. Is there a better way? (Yes I use passkeys extensively but for certain services like email, iCloud, and my password manager, a hardware option is desirable if not mandatory.) #YubiKey #YubiKeys #FIDO #FIDO2 #FIDOKey #FIDOKeys #Security

Antwortete im Thread

@sarahjamielewis I would like to hear answers to that question as well. I have not tried it myself, but I'm considering #Keycloak for something like that.

I would also suggest the hashtags #passkey #webauthn and #fido to gather the attention of the right people?

If you're ready to learn the technical details, then there is a Tour of WebAuthN here: imperialviolet.org/tourofwebau

www.imperialviolet.orgA Tour of WebAuthn

So, it has been like three months using FIDO/U2F keys instead of passwords. Both in my NetBSD and Arch systems.

I use a "medium" quality password to decrypt the filesystems and other one to decrypt the password manager. And that's it.

No password to log-in, to unlock screen, to run doas/sudo, etc. Just this little penguin and press its button.

Also, I'm using this as 2FA for all websites that support it. Lemmy doesn't. It's the only place where I don't use it, yet.

Because U2F uses the domain name, this is a strong protection against phishing. A similar domain may trick my eyes, but not the key.

I'm very bad at memorizing passwords, and worse at typing them. Unlocking the screen without typing my password like 3 times is a bless.

The problems: if my laptop is decrypted anybody with this penguin is root. It's kinda my Horcrux. Also, I need a second one stored safely as a backup.

So I officially have two horcruxes. Destroy both and I can't log-in anywhere.

#fido#u2f#infosec

For the last few months, I had a strange issue with my Fedora 40 installation which was driving me mad.

When I had the computer running for some time, I couldn't use more than one browser, because the other couldn't even start or couldn't load websites. It was happening with Firefox and any other chromium based browser. It was unpredictable and nothing conclusive was visible in the logs and strace just showed it was waiting for something I had a hard time identifying.

Then I installed Fedora 41 on a laptop and it started to happen immediately there - not just after some time, immediately!

I took the laptop out from USB-C display to look at it in another room and it stopped.

Then I vaguely remembered I put an U2F key to my screen's usb hub for convenience of use and the issues started some time after that.

Yep. It was the key. When it's connected through the USB hub in my screen, the browsers somehow "battle" for it 🤦‍♀️ It's a normal USB-A U2F key by IDEM. Never heard about such issues, and the key is working normally when connected to the computer directly.

#JustLinuxFun #Linux #U2F #FIDO #Chromium #Firefox #usb

I ordered two FIDO2 USB keys.

I want to know how (in)convenient are they.

If I can use them, I will have KeepassXC with passwords only, and a separated second factor.

Plus, this second factor won't be as attractive as smartphones to thefts. So, less chances to lost it.

I've read that a good strategy is to have a USB key for everyday use, and a second one stored in a safe place as a backup, just in case the primary one is lost or damaged.

If I understood correctly what I've read, they will be compatible with NetBSD. One can only hope xD

#fido#keepass#2fa

The FIDO Alliance, the organization that’s helping shepherd passkey adoption, announced a draft of new specifications that would let users securely move their passkeys across different password managers.

#passkeys #password #manager #fido
theverge.com/2024/10/15/242708

The Verge · Password manager makers want to let you securely transfer passkeysVon Jay Peters

New #FIDO proposal lets you securely move passkeys across platforms

The FIDO alliance has _finally_ presented something about transferring passkeys between custodians. This created the real possibility of vendor lock-in; especially if you wanted to switch devices or use a different custodian (I advocate for @bitwarden because I am biased).

This is subject to change, but great development news imo.

#passkeys #cybersecurity

bleepingcomputer.com/news/secu

BleepingComputer · New FIDO proposal lets you securely move passkeys across platformsVon Bill Toulas

#ayuda fediverso por favor
cual es el autenticador / identity provider mas sencillo que utilizar?
estoy tratando (pero atascado) de usar #authelia con #nginx_proxy_manager con esta guia: ambientnode.uk/authelia-npm/ pero estoy atascado con el apartado de #totp
busco uno que sea:
- sencillo de configurar e instalar
- que tenga #2fa #totp
- y muy idealmente, soporte para llaves fisicas (#fido)
se agradece boost

ambient_node · Secure Web Services with Authelia and Nginx Proxy ManagerIntegrate Authelia with Nginx Proxy Manager for enhanced web security.