Skip Navigation
[(late) Ciel Sundays 44] Sitting proudly

[(late) Ciel Sundays 44] Sitting proudly

Source: https://www.pixiv.net/en/artworks/116854867 Artist: https://www.pixiv.net/en/users/17834660

Sorry for waiting on this one, was kind of hoping my home lemmy server would come back from 502; but it doesn't seem like it, in the meantime I'll keep posting these and see if I can establish a second backup community for those who care.

@tsukihime @animepics #CielSundays #Tsukihime #Anime

0
Hardware security key options?
  • For many TOTP may be a good option; but my experience with TOTP has been less than subpar.

    Initially I did use TOTP like you're supposed to; but after my last phone died I had to set up TOTP on the accounts that used it *after* getting into them without it using backup codes.
    This lead me to put the TOTP stuff inside my KeePass vault (as KeePassXC supports TOTP) which is backed up (unlike most TOTP solutions I've used).
    The problem now is that my 2FA keys are stored in the same location as my passwords... (not that I'm worried about someone breaking the vault; but this is *not* how 2FA is supposed to work).

    Additionally I have some other issues with TOTP that make it far from ideal for me and hardware keys seem to be a good fit to solve my issues with TOTP.

  • Hardware security key options?
  • Let's *NOT* go that route.

    I'm very much looking for a hardware key to avoid biometrics (I can have a field day expressing my opinions on those; but in general they tend to be the weakest MFA factor and most have known working bypasses based on photos).
    This leans a little too close to that for me to consider, let alone all of the things you have to consider when putting implants in your body.

  • Hardware security key options?
  • I don't have a key yet (which is why I'm asking) and I definitely want it in combination with passwords (they can take the key using force; but they can't take thoughts out of my head just yet).

    As for android apps not working with the yubikey: try giving KeePassDX a shot; I got it from F-Droid and it does give me a hardware key field with the option to autofill with "Yubikey challenge-response".

  • Hardware security key options?

    Hardware security key options?

    I've been thinking about getting a hardware security key and have heard of yubikey before; but I want to see what my options are and if they are worth it in your opinion. My current setup is a local KeePassXC database (that I sync between my PC and phone and also acts as TOTP authenticator app), I know that KeePass supports hardware keys for unlocking the database.

    I am personally still of the belief that passwords are the safest when done right; but 2FA/MFA can greatly increase security on top of that (again, if done right). The key work work together with already existing passwords, not replace them.

    As I use linux as my primary OS I do expect it to support it and anything that doesn't I will have to pass on.

    PS: what are the things I need to know about these hardware keys that's not being talked about too much, I am very much delving into new territory and want to make sure I'm properly educated before I delve in.

    @linux @technology@lemmy.ml @technology@lemmy.world @privacy #2FA #MFA #yubikey #InfoSec #CyberSecurity

    35
    [Art] Arcueid giving Ciel's outfit a shot & Ciel in her executioner outfit (+)

    [Art] Arcueid giving Ciel's outfit a shot & Ciel in her executioner outfit (+) mainly a test post to see how lemmy deals with multi-image posts so I'm not going to try and hunt for sources, you can try iqdb yourself if you care. @tsukihime

    0
    Testing Lemmy integration

    Testing Lemmy integration @tsukihime this toot is being created from my mastodon account and should show up as a post in the tsukihime community I moderate.

    This is mostly a test to see if federation is going through properly, I might write a proper guide on this later.

    0
    Scraft161 Scraft161 @tsukihi.me

    FOSS enthusiast and anime fan.

    DM/PM's are open, just know I will respond when the 5 gremlins in my brain decide they want social interaction by majority vote.

    also, I boost a lot of stuff, if you dare follow me expect this to drown your feed if you're not active all the time, if you just want to see my posts you can hide a person's boosts on their profile and it shouldn't drown your feed.

    Posts 5
    Comments 3