mathstodon.xyz is one of the many independent Mastodon servers you can use to participate in the fediverse.
A Mastodon instance for maths people. We have LaTeX rendering in the web interface!

Server stats:

2.8K
active users

#fido

0 posts0 participants0 posts today
gtbarry<p>If we want a passwordless future, let's get our passkey story straight</p><p>Passkeys are based on public key cryptography, where two keys are paired. One key is public and can be shared with anyone, while the other is private and shared with no one.</p><p><a href="https://mastodon.social/tags/passkey" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>passkey</span></a> <a href="https://mastodon.social/tags/password" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>password</span></a> <a href="https://mastodon.social/tags/paswords" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>paswords</span></a> <a href="https://mastodon.social/tags/fido" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>fido</span></a> <a href="https://mastodon.social/tags/cryptography" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cryptography</span></a> <a href="https://mastodon.social/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a> <a href="https://mastodon.social/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a> <a href="https://mastodon.social/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a></p><p><a href="https://www.zdnet.com/article/if-we-want-a-passwordless-future-lets-get-our-passkey-story-straight/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">zdnet.com/article/if-we-want-a</span><span class="invisible">-passwordless-future-lets-get-our-passkey-story-straight/</span></a></p>
🔘 G◍M◍◍T 🔘<p>💡 Microsoft: nuovi account senza password e con passkey di default</p><p><a href="https://gomoot.com/microsoft-nuovi-account-senza-password-e-con-passkey-di-default/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">gomoot.com/microsoft-nuovi-acc</span><span class="invisible">ount-senza-password-e-con-passkey-di-default/</span></a></p><p><a href="https://mastodon.uno/tags/blog" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>blog</span></a> <a href="https://mastodon.uno/tags/fido" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>fido</span></a> <a href="https://mastodon.uno/tags/fido2" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>fido2</span></a> <a href="https://mastodon.uno/tags/microsoft" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>microsoft</span></a> <a href="https://mastodon.uno/tags/news" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>news</span></a> <a href="https://mastodon.uno/tags/password" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>password</span></a> <a href="https://mastodon.uno/tags/passwordless" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>passwordless</span></a> <a href="https://mastodon.uno/tags/picks" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>picks</span></a> <a href="https://mastodon.uno/tags/tech" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>tech</span></a> <a href="https://mastodon.uno/tags/tecnologia" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>tecnologia</span></a> <a href="https://mastodon.uno/tags/windows" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>windows</span></a></p>
Nate Allen<p>I'm sure there is a simple, totally obvious reason (no trusted central authority problem?) but it seems kind of strange to me that the <a href="https://pdx.social/tags/Fediverse" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Fediverse</span></a> doesn't allow me to truly use a single login across services via some kind of <a href="https://pdx.social/tags/FIDO" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>FIDO</span></a> compliant magic, considering that almost everyone is an <a href="https://pdx.social/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a> person and/or developer. Admittedly, I haven't thought about this too deeply. Also, where's passkey support? <a href="https://pdx.social/tags/saml" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>saml</span></a> <a href="https://pdx.social/tags/sso" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>sso</span></a></p>
Geoffrey Giebelhaus<p>With 3G ending in <a href="https://mastodon.social/tags/Canada" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Canada</span></a> I'm being forced to upgrade my otherwise perfectly good phone 😭 </p><p>Anyone have experience with the <a href="https://mastodon.social/tags/MotorolaG" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>MotorolaG</span></a> series?<br>I've been looking at the Moto G Stylus and trying to decide if it's a worthy change up or if I'll be annoyed with a stylus or the somehow lower specs than my current phone... Currently rocking a <a href="https://mastodon.social/tags/OnePlus8T" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OnePlus8T</span></a> for comparison. </p><p><a href="https://mastodon.social/tags/recommendations" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>recommendations</span></a> <a href="https://mastodon.social/tags/robelus" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>robelus</span></a> <a href="https://mastodon.social/tags/fido" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>fido</span></a></p>
Edwin G. :mapleleafroundel:<p>Rogers to charge their customers (including Fido) $3/month for 2G and 3G access. It will not apply if the phone connects to 4G or 5G. Network to shutdown starting 31 July 2025.</p><p><a href="https://mobilesyrup.com/2025/04/07/rogers-fido-3g-fee-may/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">mobilesyrup.com/2025/04/07/rog</span><span class="invisible">ers-fido-3g-fee-may/</span></a><br>- - -<br>Rogers facturera ses clients (incluant Fido) 3$/mois pour l’accès aux réseaux 2G et 3G. Cela ne s’appliquera pas si le téléphone se connecte à la 4G ou 5G. Le réseau commencera à fermer le 31 juillet 2025. </p><p>// Article en anglais //</p><p><a href="https://mstdn.moimeme.ca/tags/Canada" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Canada</span></a> <a href="https://mstdn.moimeme.ca/tags/Rogers" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Rogers</span></a> <a href="https://mstdn.moimeme.ca/tags/Fido" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Fido</span></a></p>
The Grue<p><span class="h-card" translate="no"><a href="https://mas.to/@TechConnectify" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>TechConnectify</span></a></span> Thank you so much for this video. I just watched it and it rings *every* bell. Mastodon is the only social network where I'm "active", apart from that I use <a href="https://digitalcourage.social/tags/RSS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>RSS</span></a> feeds that I picked very well. I try to use my own brain. <br>It was such a pleasure to listen to you, especially in times like these. Thank you once more.<br>(But I miss good, ancient <a href="https://digitalcourage.social/tags/FIDO" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>FIDO</span></a>-net, I must admit)</p>
David Nelson<p>People who use hardware security keys: Storing them in geographically diverse locations is a wise move but makes it impossible to quickly onboard. How do you keep track of where you’ve registered each key? A checklist in a spreadsheet is obvious but cumbersome. Is there a better way? (Yes I use passkeys extensively but for certain services like email, iCloud, and my password manager, a hardware option is desirable if not mandatory.) <a href="https://mastodon.social/tags/YubiKey" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>YubiKey</span></a> <a href="https://mastodon.social/tags/YubiKeys" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>YubiKeys</span></a> <a href="https://mastodon.social/tags/FIDO" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>FIDO</span></a> <a href="https://mastodon.social/tags/FIDO2" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>FIDO2</span></a> <a href="https://mastodon.social/tags/FIDOKey" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>FIDOKey</span></a> <a href="https://mastodon.social/tags/FIDOKeys" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>FIDOKeys</span></a> <a href="https://mastodon.social/tags/Security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Security</span></a></p>
Juergen M. Bruckner<p><span class="h-card" translate="no"><a href="https://sueden.social/@red_rooster" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>red_rooster</span></a></span> <br>Du kannst auch einen FIDO2 Stick verwenden - wo das halt geht.</p><p><a href="https://mastodon.bruckner.email/tags/fido" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>fido</span></a> <a href="https://mastodon.bruckner.email/tags/fido2" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>fido2</span></a> <a href="https://mastodon.bruckner.email/tags/opensource" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>opensource</span></a> <a href="https://mastodon.bruckner.email/tags/totp" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>totp</span></a> <a href="https://mastodon.bruckner.email/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a></p>
Claus Holm Christensen<p><span class="h-card" translate="no"><a href="https://mastodon.social/@sarahjamielewis" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>sarahjamielewis</span></a></span> I would like to hear answers to that question as well. I have not tried it myself, but I'm considering <a href="https://mastodon.social/tags/Keycloak" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Keycloak</span></a> for something like that.</p><p>I would also suggest the hashtags <a href="https://mastodon.social/tags/passkey" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>passkey</span></a> <a href="https://mastodon.social/tags/webauthn" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>webauthn</span></a> and <a href="https://mastodon.social/tags/fido" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>fido</span></a> to gather the attention of the right people?</p><p>If you're ready to learn the technical details, then there is a Tour of WebAuthN here: <a href="https://www.imperialviolet.org/tourofwebauthn/tourofwebauthn.html" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">imperialviolet.org/tourofwebau</span><span class="invisible">thn/tourofwebauthn.html</span></a></p>
KEXP 🎶 #NowPlaying Bot<p>🔊 <a href="https://mastodonapp.uk/tags/NowPlaying" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>NowPlaying</span></a> on <a href="https://mastodonapp.uk/tags/KEXP" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>KEXP</span></a>'s <a href="https://mastodonapp.uk/tags/Continent" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Continent</span></a></p><p>Fido:<br> 🎵 Awolowo</p><p><a href="https://mastodonapp.uk/tags/Fido" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Fido</span></a> </p><p><a href="https://open.spotify.com/track/1136eJrkWsDvReASbjLTaU" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">open.spotify.com/track/1136eJr</span><span class="invisible">kWsDvReASbjLTaU</span></a></p>
LavX News<p>Unlocking Security: The Best Physical Security Keys of 2025</p><p>In an era where data breaches are rampant, physical security keys are becoming essential for safeguarding online accounts. This article dives deep into the top security keys available in 2025, evaluat...</p><p><a href="https://news.lavx.hu/article/unlocking-security-the-best-physical-security-keys-of-2025" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://</span><span class="ellipsis">news.lavx.hu/article/unlocking</span><span class="invisible">-security-the-best-physical-security-keys-of-2025</span></a></p><p><a href="https://mastodon.cloud/tags/news" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>news</span></a> <a href="https://mastodon.cloud/tags/tech" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>tech</span></a> <a href="https://mastodon.cloud/tags/Cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Cybersecurity</span></a> <a href="https://mastodon.cloud/tags/YubiKey" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>YubiKey</span></a> <a href="https://mastodon.cloud/tags/FIDO" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>FIDO</span></a></p>
Tao of Mac<p>Passkey technology and its Usability</p><p>The “not (quite) ready for primetime” tag is eminently applicable here. (...)</p><p><a href="https://mastodon.social/tags/fido" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>fido</span></a> <a href="https://mastodon.social/tags/madness" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>madness</span></a> <a href="https://mastodon.social/tags/passkeys" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>passkeys</span></a> <a href="https://mastodon.social/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a> <a href="https://mastodon.social/tags/usability" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>usability</span></a> <a href="https://mastodon.social/tags/webauthn" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>webauthn</span></a></p><p><a href="https://taoofmac.com/space/links/2024/12/30/1400" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">taoofmac.com/space/links/2024/</span><span class="invisible">12/30/1400</span></a></p>
release_candidate<p>So, it has been like three months using FIDO/U2F keys instead of passwords. Both in my NetBSD and Arch systems.</p><p>I use a "medium" quality password to decrypt the filesystems and other one to decrypt the password manager. And that's it.</p><p>No password to log-in, to unlock screen, to run doas/sudo, etc. Just this little penguin and press its button.</p><p>Also, I'm using this as 2FA for all websites that support it. Lemmy doesn't. It's the only place where I don't use it, yet.</p><p>Because U2F uses the domain name, this is a strong protection against phishing. A similar domain may trick my eyes, but not the key.</p><p>I'm very bad at memorizing passwords, and worse at typing them. Unlocking the screen without typing my password like 3 times is a bless.</p><p>The problems: if my laptop is decrypted anybody with this penguin is root. It's kinda my Horcrux. Also, I need a second one stored safely as a backup.</p><p>So I officially have two horcruxes. Destroy both and I can't log-in anywhere.</p><p><a href="https://mastodon.bsd.cafe/tags/fido" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>fido</span></a> <a href="https://mastodon.bsd.cafe/tags/u2f" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>u2f</span></a> <a href="https://mastodon.bsd.cafe/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a> <a href="https://mastodon.bsd.cafe/tags/NetBSD" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>NetBSD</span></a> <a href="https://mastodon.bsd.cafe/tags/arch" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>arch</span></a> <a href="https://mastodon.bsd.cafe/tags/keepass" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>keepass</span></a> <a href="https://mastodon.bsd.cafe/tags/password" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>password</span></a> <a href="https://mastodon.bsd.cafe/tags/horcrux" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>horcrux</span></a></p>
Kayla Eilhart (en)<p>For the last few months, I had a strange issue with my Fedora 40 installation which was driving me mad.<br><br>When I had the computer running for some time, I couldn't use more than one browser, because the other couldn't even start or couldn't load websites. It was happening with Firefox and any other chromium based browser. It was unpredictable and nothing conclusive was visible in the logs and strace just showed it was waiting for something I had a hard time identifying.<br><br>Then I installed Fedora 41 on a laptop and it started to happen immediately there - not just after some time, immediately!<br><br>I took the laptop out from USB-C display to look at it in another room and it stopped.<br><br>Then I vaguely remembered I put an U2F key to my screen's usb hub for convenience of use and the issues started some time after that.<br><br>Yep. It was the key. When it's connected through the USB hub in my screen, the browsers somehow "battle" for it 🤦‍♀️ It's a normal USB-A U2F key by IDEM. Never heard about such issues, and the key is working normally when connected to the computer directly.<br><br><a href="https://gts.eilhart.cz/tags/justlinuxfun" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>JustLinuxFun</span></a> <a href="https://gts.eilhart.cz/tags/linux" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Linux</span></a> <a href="https://gts.eilhart.cz/tags/u2f" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>U2F</span></a> <a href="https://gts.eilhart.cz/tags/fido" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>FIDO</span></a> <a href="https://gts.eilhart.cz/tags/chromium" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Chromium</span></a> <a href="https://gts.eilhart.cz/tags/firefox" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Firefox</span></a> <a href="https://gts.eilhart.cz/tags/usb" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>usb</span></a></p>
chrysn<p>PSA for <a href="https://chaos.social/tags/IdAustria" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IdAustria</span></a> users: After a local attack on YubiKey devices (CVSS 4.9), A-Trust has delisted them from enrollment with ID-Austria via <a href="https://chaos.social/tags/WebAuthn" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>WebAuthn</span></a>.<br>Apart from factually being an overreaction (they demand <a href="https://chaos.social/tags/FIDO" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>FIDO</span></a> Level 2 which scalable attacks, and that attack is neither), they have not reinstated those devices in the fixed revisions of the vendor; let's see if they'll see reason 🤔<br><a href="https://www.yubico.com/support/security-advisories/ysa-2024-03/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">yubico.com/support/security-ad</span><span class="invisible">visories/ysa-2024-03/</span></a><br><a href="https://a-trust.at/de/%C3%BCber_uns/newsbereich/20240905_de_post.html" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">a-trust.at/de/%C3%BCber_uns/ne</span><span class="invisible">wsbereich/20240905_de_post.html</span></a></p>
bertrand 🏃 👨‍💻 🎸<p><span class="h-card" translate="no"><a href="https://epistolary.org/@vees" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>vees</span></a></span> I guess one reason is that if you have n passkeys, it takes one export/import operation to migrate from one passkey manager to another (yes, leaving passkeys in the legacy location), and it takes n operations to generate new passkeys (and requires n successful connections at a given time so definitely more prone to errors) <br><a href="https://piaille.fr/tags/fido" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>fido</span></a> <a href="https://piaille.fr/tags/Passkeys" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Passkeys</span></a></p>
Rob Carlson :ally: :BLM:<p>The <a href="https://epistolary.org/tags/FIDO" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>FIDO</span></a> Alliance is working on the Credential Exchange Protocol to make <a href="https://epistolary.org/tags/Passkeys" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Passkeys</span></a> more portable or exportable, but why? Passkeys can and should be disposable. Your export path from one passkey manager to another should be the list of all the providers you need to generate. It's not like they take more than milliseconds to generate, and why set yourself up for a situation where valid keys are in multiple legacy locations?</p>
release_candidate<p>After some pam configs, I can use the USB keys to authenticate `login` and `doas` instead of password.</p><p><a href="https://mastodon.bsd.cafe/tags/u2f" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>u2f</span></a> <a href="https://mastodon.bsd.cafe/tags/pam" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>pam</span></a> <a href="https://mastodon.bsd.cafe/tags/fido" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>fido</span></a> <a href="https://mastodon.bsd.cafe/tags/fido2" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>fido2</span></a> <a href="https://mastodon.bsd.cafe/tags/NetBSD" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>NetBSD</span></a></p>
release_candidate<p>I ordered two FIDO2 USB keys.</p><p>I want to know how (in)convenient are they.</p><p>If I can use them, I will have KeepassXC with passwords only, and a separated second factor.</p><p>Plus, this second factor won't be as attractive as smartphones to thefts. So, less chances to lost it.</p><p>I've read that a good strategy is to have a USB key for everyday use, and a second one stored in a safe place as a backup, just in case the primary one is lost or damaged.</p><p>If I understood correctly what I've read, they will be compatible with NetBSD. One can only hope xD</p><p><a href="https://mastodon.bsd.cafe/tags/fido" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>fido</span></a> <a href="https://mastodon.bsd.cafe/tags/keepass" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>keepass</span></a> <a href="https://mastodon.bsd.cafe/tags/2fa" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>2fa</span></a> <a href="https://mastodon.bsd.cafe/tags/NetBSD" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>NetBSD</span></a> <a href="https://mastodon.bsd.cafe/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a></p>
Avoid the Hack! :donor:<p>New <a href="https://infosec.exchange/tags/FIDO" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>FIDO</span></a> proposal lets you securely move passkeys across platforms</p><p>The FIDO alliance has _finally_ presented something about transferring passkeys between custodians. This created the real possibility of vendor lock-in; especially if you wanted to switch devices or use a different custodian (I advocate for <span class="h-card" translate="no"><a href="https://fosstodon.org/@bitwarden" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>bitwarden</span></a></span> because I am biased).</p><p>This is subject to change, but great development news imo.</p><p><a href="https://infosec.exchange/tags/passkeys" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>passkeys</span></a> <a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a> </p><p><a href="https://www.bleepingcomputer.com/news/security/new-fido-proposal-lets-you-securely-move-passkeys-across-platforms/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">bleepingcomputer.com/news/secu</span><span class="invisible">rity/new-fido-proposal-lets-you-securely-move-passkeys-across-platforms/</span></a></p>