Recommended Posts

18 minutes ago, jnelsoninjax said:

Is there any difference in the physical keys made by Google or YubiKey, etc? Do they all function the same way?

They might provide some overlap features, but no. Google’s key is more limited (not talking about connectivity), and the last I checked, just as expensive as Yubikey. Plus I don’t trust Google with something like that. 

3 hours ago, adrynalyne said:

They might provide some overlap features, but no. Google’s key is more limited (not talking about connectivity), and the last I checked, just as expensive as Yubikey. Plus I don’t trust Google with something like that. 

How about Solokeys? They are billing themselves as open source. Paging @BudMancan I get your insight?

9 minutes ago, jnelsoninjax said:

How about Solokeys? They are billing themselves as open source.

I don’t know enough about them to say either way. 
 

I guess I should clarify my last comment. Yubikey has different types of keys. Their full-featured one has more features. Their FIDO/2 keys are more comparable to what Google and Solokey offers. AFAIK, Yubikey firmware also offers some open source, but I don’t know to what extent. 
 

 

What is your planned use for whatever key you might happen to get?

 

I have a hard time justify their use for most things to be honest.  What is the scenario that you will use it?  To auth to some site on your phone or your phone itself even - so your really going to carry this key with you, along with your phone?  And pop it out every time you need to do xyz?

 

Are you going to use it to log into your computer - in your house?  Really?  Or you going to just leave it plugged into your PC all the time?

 

Now if you were going to use it say access your bank website that you only access on rare occasions, or maybe to access your crypto exchange account.

 

Don't get me wrong - they do have their use for sure.. But without the scenarios you plan on using it..

 

Keeping in mind that all security is always going to be something extra that has to be done.. The more "extra" that thing is - the less likely it will ever be used.  Or will be circumvented for ease of use that defeats the whole purpose.

 

Give you a perfect example of this in a work environment, with IT professionals.. So to login to the laptops you needed tiks card, got specific certs on it, etc. Because the laptop drive is encrypted.  What your suppose to do is carry said card in your wallet.  And place into the laptop when your using it, then say when you go home and putting the laptop in your bag where it might be stolen.. Or really even say you were going out for a business lunch or something and leaving your laptop at the desk.  The card should go with you.. 

 

Guess what happens.. Users just left the card in their laptops 24/7 - shoot they even cut off the end of the card so it didn't stick out so they could just slide it into their bags when leaving.  So they leave said laptop bag in their car, and it gets stolen, or leave it in the uber or bus.. The whole point of the 2fa auth token is defeated because it was "too much" effort to take it in and out ;)

 

So I ask - what is the scenario of use?  Are you going to put the key in a safe place - and only use it to access your crypo/bank account which is something you don't do every day?  Or you plan on using it to auth to say neowin ;)  Which you do every day, or multiple times a day.. So the thing ends up sticking out the usb port of your PC 24/7/365 ;)

 

My 2fa is my phone.. I have it with my 24/7/365 - other than when sleeping (right next to me) or taking a shower - again most likely on the sink in the bathroom with me..  What are you going to do with this key?  Are you going to carry it with you on a chain around your neck.. And put it into a device, and take it out the device every time you need to auth?

30 minutes ago, BudMan said:

What is your planned use for whatever key you might happen to get?

 

I have a hard time justify their use for most things to be honest.  What is the scenario that you will use it?  To auth to some site on your phone or your phone itself even - so your really going to carry this key with you, along with your phone?  And pop it out every time you need to do xyz?

 

Are you going to use it to log into your computer - in your house?  Really?  Or you going to just leave it plugged into your PC all the time?

 

Now if you were going to use it say access your bank website that you only access on rare occasions, or maybe to access your crypto exchange account.

 

Don't get me wrong - they do have their use for sure.. But without the scenarios you plan on using it..

 

Keeping in mind that all security is always going to be something extra that has to be done.. The more "extra" that thing is - the less likely it will ever be used.  Or will be circumvented for ease of use that defeats the whole purpose.

 

Give you a perfect example of this in a work environment, with IT professionals.. So to login to the laptops you needed tiks card, got specific certs on it, etc. Because the laptop drive is encrypted.  What your suppose to do is carry said card in your wallet.  And place into the laptop when your using it, then say when you go home and putting the laptop in your bag where it might be stolen.. Or really even say you were going out for a business lunch or something and leaving your laptop at the desk.  The card should go with you.. 

 

Guess what happens.. Users just left the card in their laptops 24/7 - shoot they even cut off the end of the card so it didn't stick out so they could just slide it into their bags when leaving.  So they leave said laptop bag in their car, and it gets stolen, or leave it in the uber or bus.. The whole point of the 2fa auth token is defeated because it was "too much" effort to take it in and out ;)

 

So I ask - what is the scenario of use?  Are you going to put the key in a safe place - and only use it to access your crypo/bank account which is something you don't do every day?  Or you plan on using it to auth to say neowin ;)  Which you do every day, or multiple times a day.. So the thing ends up sticking out the usb port of your PC 24/7/365 ;)

 

My 2fa is my phone.. I have it with my 24/7/365 - other than when sleeping (right next to me) or taking a shower - again most likely on the sink in the bathroom with me..  What are you going to do with this key?  Are you going to carry it with you on a chain around your neck.. And put it into a device, and take it out the device every time you need to auth?

I’m not OP but I will give you my uses for it. 
 

My Yubikey stays with me at all times, on my key chain. I use it where I can, but mostly to add additional protection to LastPass, GitHub repos, and Gmail accounts. I have several keys that are setup for these sites. In addition, I carry my Authenticator info on my keys, so I can install Yubikey Authenticator safely on any machine and if the key isn’t plugged in, the cycling OTPs aren’t present. A FIDO/2 key isn’t going to be as useful to someone like me. 
 


 

 

55 minutes ago, BudMan said:

What is your planned use for whatever key you might happen to get?

 

I have a hard time justify their use for most things to be honest.  What is the scenario that you will use it?  To auth to some site on your phone or your phone itself even - so your really going to carry this key with you, along with your phone?  And pop it out every time you need to do xyz?

 

Are you going to use it to log into your computer - in your house?  Really?  Or you going to just leave it plugged into your PC all the time?

 

Now if you were going to use it say access your bank website that you only access on rare occasions, or maybe to access your crypto exchange account.

 

Don't get me wrong - they do have their use for sure.. But without the scenarios you plan on using it..

 

Keeping in mind that all security is always going to be something extra that has to be done.. The more "extra" that thing is - the less likely it will ever be used.  Or will be circumvented for ease of use that defeats the whole purpose.

 

Give you a perfect example of this in a work environment, with IT professionals.. So to login to the laptops you needed tiks card, got specific certs on it, etc. Because the laptop drive is encrypted.  What your suppose to do is carry said card in your wallet.  And place into the laptop when your using it, then say when you go home and putting the laptop in your bag where it might be stolen.. Or really even say you were going out for a business lunch or something and leaving your laptop at the desk.  The card should go with you.. 

 

Guess what happens.. Users just left the card in their laptops 24/7 - shoot they even cut off the end of the card so it didn't stick out so they could just slide it into their bags when leaving.  So they leave said laptop bag in their car, and it gets stolen, or leave it in the uber or bus.. The whole point of the 2fa auth token is defeated because it was "too much" effort to take it in and out ;)

 

So I ask - what is the scenario of use?  Are you going to put the key in a safe place - and only use it to access your crypo/bank account which is something you don't do every day?  Or you plan on using it to auth to say neowin ;)  Which you do every day, or multiple times a day.. So the thing ends up sticking out the usb port of your PC 24/7/365 ;)

 

My 2fa is my phone.. I have it with my 24/7/365 - other than when sleeping (right next to me) or taking a shower - again most likely on the sink in the bathroom with me..  What are you going to do with this key?  Are you going to carry it with you on a chain around your neck.. And put it into a device, and take it out the device every time you need to auth?

Honestly I was just asking because I read an article on Gizmodo that suggested that we should be using them as opposed to the cell phone, so I am not sure that I am going to buy any, it was mainly just a question for my own information.

On 30/04/2021 at 16:04, jnelsoninjax said:

Honestly I was just asking because I read an article on Gizmodo that suggested that we should be using them as opposed to the cell phone, so I am not sure that I am going to buy any, it was mainly just a question for my own information.

It's great for security and arguably the best in terms of what's generally available. The thing is, it's overkill for the vast majority of typical use cases. Online banking and cryptocurrency exchange accounts come to mind but so few banks even offer 2FA, let alone support for physical security keys. Personally, I'd only use it for cryptocurrency stuff. In most cases, using an authenticator app is good enough.


With that said, I don't think there's anything wrong with using it out of curiosity. SoloKeys seems like a good one because it uses open source firmware.

12 hours ago, Yusuf M. said:

It's great for security and arguably the best in terms of what's generally available. The thing is, it's overkill for the vast majority of typical use cases. Online banking and cryptocurrency exchange accounts come to mind but so few banks even offer 2FA, let alone support for physical security keys. Personally, I'd only use it for cryptocurrency stuff. In most cases, using an authenticator app is good enough.


With that said, I don't think there's anything wrong with using it out of curiosity. SoloKeys seems like a good one because it uses open source firmware.

Agreed on it being overkill for a lot of people. I do everything overkill though.

12 hours ago, Yusuf M. said:

It's great for security and arguably the best in terms of what's generally available. The thing is, it's overkill for the vast majority of typical use cases. Online banking and cryptocurrency exchange accounts come to mind but so few banks even offer 2FA, let alone support for physical security keys. Personally, I'd only use it for cryptocurrency stuff. In most cases, using an authenticator app is good enough.


With that said, I don't think there's anything wrong with using it out of curiosity. SoloKeys seems like a good one because it uses open source firmware.

few banks offer 2FA? I haven't come across one that didn't in years... even local banks around me that are smaller have it

2 minutes ago, neufuse said:

few banks offer 2FA? I haven't come across one that didn't in years... even local banks around me that are smaller have it

Yeah but do they offer FIDO/2 ?


OP I think was only looking at these keys. 

6 minutes ago, neufuse said:

no, but I was replying to this line "but so few banks even offer 2FA, let alone support for physical security keys."

My credit union has OTK that they send via SMS whenever you call and talk to them, and 2FA via SMS on the mobile app.

45 minutes ago, jnelsoninjax said:

My credit union has OTK that they send via SMS whenever you call and talk to them, and 2FA via SMS on the mobile app.

My bank is so secure they wont let you change anything about your account unless you do it at the original branch.... problem for me is the original branch closed  😆 every time I call in for something they want a password and the location I took out my first account at.... which is a bit ridicilous... and to close an account you have to visit the original branch.. maybe that is something to stop you from closing it? lol....

On 30/04/2021 at 08:52, jnelsoninjax said:

Is there any difference in the physical keys made by Google or YubiKey, etc? Do they all function the same way?

I have both.  Googles can't be used by default with Windows 10, but it obviously works for websites.  They function similarly but you can set a pin on the Yubikey (and promptly forget whatever the hell it was heh.)

 

Checking if the Yubikey can work for logins now.  I really don't know, but they have some software for it.

Just a small comment ill add about YubiKey's...

 

those who want to use these basically need two of them at minimum. one for general use and one for a backup stored in a secure location. that helps ensure you won't get locked out of your Google account for example since you register both keys to the account. so even if you lose one, you can always use the backup to sign-in to the Google account, remove the lost key, then you can simply buy another key and register that to the account and you will now have two keys registered once again.

 

p.s. I just have two of the standard/basic YubiKey's. but currently they are a bit pricier than what I paid for mine not all that long ago as for a couple of the basic ones it's $49 now where as I got two at a discount for $30. because for the price I paid it was nice peace of mind, but at $49 I could easily see how some might have second thoughts about using them as at that price it's a little steep. NOTE: YubiKey's work on Linux Mint but not by default. but it's easy enough to get them working as you just copy and paste the text from... https://github.com/Yubico/libu2f-host/blob/master/70-u2f.rules to a file (just load up Text Editor(Xed)) named '70-u2f.rules' and save it to "/etc/udev/rules.d/" then reboot. works on Chrome/Firefox (may work on other browsers but I never tested). but I noticed if a person is running their browser in Firejail (sandbox), to sign into ones Google account for example, you got to run the browser normally, sign-in into ones Google account with the YubiKey, then exit the browser, reload it in the Firejail sandbox and you will be fine here since it's using the cookie from previous session.

Edited by ThaCrip
49 minutes ago, neufuse said:

My bank is so secure they wont let you change anything about your account unless you do it at the original branch.... problem for me is the original branch closed  😆 every time I call in for something they want a password and the location I took out my first account at.... which is a bit ridicilous... and to close an account you have to visit the original branch.. maybe that is something to stop you from closing it? lol....

I'd move to a new bank, if I were you...

2 hours ago, neufuse said:

My bank is so secure they wont let you change anything about your account unless you do it at the original branch.... problem for me is the original branch closed  😆 every time I call in for something they want a password and the location I took out my first account at.... which is a bit ridicilous... and to close an account you have to visit the original branch.. maybe that is something to stop you from closing it? lol....

Is your bank located in Egypt? :D that experience is awfully familiar to one I had...

Just now, adrynalyne said:

Why because it’s secure? 

Not saying it's secure, just saying you can't do anything unless you come to the main branch.

 

21 minutes ago, neufuse said:

not exactly easy when you have a mortgage there, that's an expensive move

Oh, that says a lot...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Even though MS had to sunset the Windows Subsystem for Android, you can apparently use BlueStacks to run Android in Windows now. I haven't tested this yet, so if anyone has any feedback, I'd love to hear it.
    • Or, if you want to teach your kids how to hallucinate and lie like AI slop, introduce them to a Crazy MAGA Grandpa on LSD.
    • Ventoy 1.1.14 by Razvan Serea Ventoy is an open source tool to create bootable USB drive for ISO/WIM/IMG/VHD(x)/EFI files. With Ventoy, you don't need to format the disk over and over, you just need to copy the ISO/WIM/IMG/VHD(x)EFI files to the USB drive and boot them directly. You can copy many files at a time and ventoy will give you a boot menu to select them. Both Legacy BIOS and UEFI are supported in the same way. Most type of OS supported (Windows/WinPE/Linux/Unix/Vmware/Xen...) Ventoy features: 100% open source Simple to use Fast (limited only by the speed of copying iso file) Directly boot from ISO/WIM/IMG/VHD(x)/EFI file, no extraction needed Legacy + UEFI supported in the same way UEFI Secure Boot supported (since 1.0.07+) Persistence supported (since 1.0.11+) MBR and GPT partition style supported (1.0.15+) WIM files boot supported (Legacy + UEFI) (1.0.12+) IMG files boot supported (Legacy + UEFI) (1.0.19+) Auto installation supported (1.0.09+) File injection supported (1.0.16+) ISO files larger than 4GB supported Native boot menu style for Legacy & UEFI Most type of OS supported(Windows/WinPE/Linux/Unix/Vmware/Xen...), 550+ iso files tested Not only boot but also complete installation process ISO files can be listed in List mode/TreeView mode Linux vDisk boot supported (vdi/vhd/raw) "Ventoy Compatible" concept Plugin Framework Menu Alias/Menu Style/Customized Menu supported USB drive write-protected support USB normal use unaffected Data nondestructive during version upgrade No need to update Ventoy when a new distro is released Ventoy 1.1.14 changelog: Update secure boot shim file to solve the UEFI CA 2023 issue. The new release use a new CA, so you need to enroll the new key for the first boot time. VentoyPlugson update synchronously. Global control plugin add a VTOY_SECURE_BOOT_POLICY option. Notes Download: Ventoy 1.1.14 | 15.9 MB (Open Source) Download: Ventoy Live CD | 187.0 MB Link: Ventoy Home Page | Project Page @GitHub | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Save 83% on PRO$PER Lifetime Pass by Sterling Stock Picker by Steven Parker Today's deal from our Apps + Software section of the Neowin Deals store, lets you save 83% on PRO$PER Lifetime Pass by Sterling Stock Picker. Note: Only available to NEW users. This deal is exclusive to Stacksocial. Gain Financial Freedom Through Expert Education PRO$PER Financial Success System is a comprehensive financial education platform designed to help individuals build stronger money habits, make informed financial decisions, and create a clear path toward long-term wealth. The program includes 12+ in-depth financial courses, more than 150 lessons, personalized learning pathways, and a financial dashboard that tracks your progress and goals. Members receive lifetime access to expert-led training from seasoned financial educator Jaden Sterling, along with exclusive resources such as worksheets, eBooks, webinars, and practical implementation tools. The platform also features Finley AI, an intelligent financial coaching assistant that delivers personalized guidance, recommendations, and educational support tailored to your unique financial journey. Ideal for anyone looking to reduce debt, improve budgeting skills, grow investments, prepare for retirement, or achieve greater financial confidence and stability. Whether you're a beginner learning the fundamentals of personal finance or someone seeking to strengthen an existing financial plan, the platform provides actionable strategies and step-by-step guidance to help you reach your goals. Through personalized recommendations, community support, and AI-powered coaching, members can develop better financial habits, avoid common money mistakes, and stay focused on long-term success. By combining education with practical implementation, PRO$PER empowers users to build sustainable wealth, improve financial security, and create a stronger foundation for their future. Comprehensive Financial Training Made Simple Financial Success Blueprint: Learn the fundamentals of budgeting, saving, debt reduction, investing, retirement planning, and wealth creation. 12+ Comprehensive Financial Courses: Access a growing library of expert-led courses covering personal finance and money management. 150+ Financial Lessons: Explore a wide range of educational content designed to strengthen your financial knowledge. Lifetime Access: Enjoy unlimited access to all current and future training materials at your own pace. Self-Paced Learning: Study anytime, anywhere, with no deadlines or fixed class schedules. Expert-Led Instruction: Learn from experienced financial educator and mentor Jaden Sterling. Step-by-Step Learning Paths: Follow structured roadmaps that simplify complex financial topics. AI-Powered Support for Financial Success Finley AI Financial Coach: Get on-demand guidance, insights, and support from an AI-powered financial assistant. Personalized Financial Dashboard: Track financial goals, confidence levels, progress, and areas for improvement. Tailored Learning Recommendations: Receive customized course suggestions based on your profile and objectives. Investment & Wealth-Building Insights: Explore strategies to grow wealth and make informed financial decisions. Resources and Support to Thrive Financially Decision-Making Support: Gain confidence in managing money, investing, and long-term planning. Community Support Network: Connect with like-minded members, share experiences, and learn from others. Exclusive Educational Resources: Access eBooks, worksheets, webinars, guides, and practical financial tools. Actionable Learning Approach: Apply concepts immediately through exercises, implementation strategies, and real-world examples. Good to know Length of access: Lifetime Redemption deadline: redeem your code within 60 days of purchase Access Options: Desktop and mobile Max number of devices: Unlimited Updates included Only available to NEW users PRO$PER Lifetime Pass by Sterling Stock Picker normally costs $499 but it can be yours for only $79.99, that's a saving of $420 (83%) off! For terms, and more details click the link below. PRO$PER Lifetime Pass by Sterling Stock Picker at 83% off (was $499) Although priced in U.S. dollars, this deal is available for digital purchase worldwide. Support queries If you have queries or need support for any of the Neowin Deals, please use the contact form here. Neowin Deals are managed and sold by StackCommerce who represent Neowin on an affiliate basis. Why we post these deals We post these because we earn commission on each sale so as not to rely solely on advertising, which many of our readers block. It all helps toward paying staff reporters, servers and hosting costs. So for those that keep moaning and complaining, be thankful we're still online for you to even do that. Other ways to support Neowin Whitelist Neowin by not blocking our ads Create a free member account to see fewer ads Make a donation to support our day to day running costs Subscribe to Neowin - for $14 a year, or $28 a year for an ad-free experience Disclosure: Neowin benefits from revenue of each sale made through our branded deals site powered by StackCommerce.
    • Windows 10 is end-of-life (EOL) anyway.
  • Recent Achievements

    • Dedicated
      Scoobystu earned a badge
      Dedicated
    • First Post
      Tom Schmidt earned a badge
      First Post
    • One Month Later
      D0nn13 earned a badge
      One Month Later
    • Rookie
      +ChiefOfNeo went up a rank
      Rookie
    • One Year In
      Tom Schmidt earned a badge
      One Year In
  • Popular Contributors

    1. 1
      +primortal
      457
    2. 2
      +Edouard
      177
    3. 3
      PsYcHoKiLLa
      123
    4. 4
      Michael Scrip
      83
    5. 5
      Xenon
      76
  • Tell a friend

    Love Neowin? Tell a friend!