← Home ← Back to /g/

Thread 106485671

33 posts 12 images /g/
Anonymous No.106485671 >>106485725 >>106485764 >>106485789 >>106485797 >>106486159 >>106486394 >>106489047 >>106489134 >>106489695 >>106489815 >>106490501
How is this thing any better than a password?
Anonymous No.106485712 >>106485725 >>106485926
if i steal this i can access your system

if i need your password i instead have to break your fingers, which is much more fun
Anonymous No.106485725 >>106485763
>>106485712
You still need the FIDO/U2F/PIV PIN.
>>106485671 (OP) It lets you use TOTP across devices without needing a phone.
Anonymous No.106485763 >>106487994
>>106485725
most password managers can do TOTP
Anonymous No.106485764
>>106485671 (OP)
Can't be phished no matter how hard the user messes up
Anonymous No.106485789 >>106485835 >>106489108
>>106485671 (OP)
NFC never fucking works for me
have to always plug it in
hate this shit
Anonymous No.106485797 >>106486064
>>106485671 (OP)
It's great for the elderly or the tech illiterate so they can just plug and authenticate instead of writing down a password or reusing the same simple passphrase they use for every service.
Anonymous No.106485835
>>106485789
Works on my machine.
Anonymous No.106485926 >>106486152
>>106485712
>if i need your password i instead have to break your fingers, which is much more fun
How's he supposed to be able to type on a keyboard if you break his fingers retard? Do you expect him to type that shit out with his feet?
Fucking amateurs I swear.
Anonymous No.106486064 >>106489251
>>106485797
>Thinks FIDO is passkeys
Anonymous No.106486152 >>106486541
>>106485926
He could just tell you the password and you type it.
Anonymous No.106486159
>>106485671 (OP)
>How is this thing any better than a password?
it's not, next question
Anonymous No.106486394
>>106485671 (OP)
This lets you remember a simple pin instead of a complicated password
Pin strength is about as secure because it blocks if you fail too many times.
And ofc it's a physical device so you need to physically steal it to even use it which is much harder than penis I'm bored
Anonymous No.106486541 >>106486582 >>106486596 >>106489009
>>106486152
>He could just tell you the password and you type it.
That could work, unless I miss hear him. I'm very easily distracted sometimes. Also the whole being tortured thing might leave him hyper ventilating and nervously spelling it out to fast.
Anonymous No.106486582 >>106487950
>>106486541
Most people will give it right up. People aren't super tough guys like in the movies or what they pretend to be. You don't need to go hardcore, just things that are painful enough and bring them fear for worse.
Anonymous No.106486596 >>106487950
>>106486541
oh no, an excuse to break another finger. how awful.
Anonymous No.106487950
>>106486596
>>106486582
>oh no, an excuse to break another finger. how awful.
Ummm sorry Mr. prisoner I'll listen more clearly this time... I was originally only gonna break like two fingers originally, please speak at a slower pace.
Anonymous No.106487994 >>106488112 >>106489135
>>106485763
>turn on MFA
>put your TOTP within your password manager
might as well just turn off MFA at that point.
Anonymous No.106488112
>>106487994
if they let you then sure turn it off
Anonymous No.106489009
>>106486541
I think you are too retarded to be a functional autist.
Anonymous No.106489047 >>106489199
>>106485671 (OP)
yubiko no pico
Anonymous No.106489108
>>106485789
android and fido2 is very finicky, try using u2f instead.
Anonymous No.106489134 >>106489172
>>106485671 (OP)
It only protects against one vector of attack at the expense of exposing to another. If someone steals your yubi key, they can easily log into any account.
Anonymous No.106489135
>>106487994
storing totp in your pw manager still protects you against website leaks.
the only disadvantage is if your pw database itself gets leaked, in which case you are fucked, totp or not. this happens much less frequently than a website leaking credentials (unless tarded).
imo it's much better to increase the security of the pw manager (with keyfiles, hardware keys), than storing totp in another device.
Anonymous No.106489172
>>106489134
>If someone steals your yubi key, they can easily log into any account
What do you suppose the M in MFA stands for?
Anonymous No.106489199
>>106489047
kek
Anonymous No.106489225
its secure only if you securely store it up your bum
Anonymous No.106489251
>>106486064
FIDO can function for webauthn logins, they just aren't syncable.

Cross device syncing is the main feature of passkeys.
Anonymous No.106489612 >>106489662
What happens if it fails or you lose it? Bye bye accounts. I will never use anything like that or 2FA.
Anonymous No.106489662
>>106489612
That's why you buy two and keep one safe. You know, exactly how you do it with your passwords?
Anonymous No.106489695
>>106485671 (OP)
its like those old computers that needed a physical key to turn on but you can't just jam a bic pen in there

and a yubi, whilst a cybsec larper meme, are still superior to smart cards for the sole reason that not every computer has a smart card slot but some shit is seriously wrong if you dont have usb ports.

its also mainly for "secure environments" or companies without a BYD policy where phone meme MFA is inappropriate. personally i have an RSA key that cycles through numbers (i didnt buy it, its for work)
Anonymous No.106489815
>>106485671 (OP)
for the same reason multifactor exists if someone steals your password but not the key you are still secure. if someone steals your key but not the password you are secure.

just makes hacking you harder
teh.cmn No.106490501
>>106485671 (OP)
because it's not a replacement for password it's an additonal layer of security and they both your password and that device