Spyke

Syndicated from the fediverse. Read and engage on the original instance.

View original on hackertalks.com
applied_paranoia·Applied Paranoiabyjet

What is your hardware key strategy?

I like multiple factors. I played with a bunch of different hardware security tokens over time. Fingerprint reading on the token is pretty good, I don't like the idea of typing in a PIN to an untrusted computer to talk to the token. I played with the only key, and it's interesting, but it's been pretty much abandoned by its original developers. So I think it's in dead end. But it did have a physical input keypad on the key. So the PIN didn't have to trust the computer that's nice

What do you use? What is your strategy? Any fun anecdotes?

View original on hackertalks.com
10

3 replies

If I don’t trust the computer with my PIN, I don’t trust it to handle an access token. ¯\_(ツ)_/¯

4

the trouble is many tokens the PIN overrides the fingerprint, so giving the pin to a host reduces it from something you have/something you are to just something you have, something you know. And computers are good at knowing things.

3

i would like to try out the yubikey bio enterprise, but they wont sell it to low volume operations like mine

2

You reached the end

What is your hardware key strategy? | Spyke