PaulGherkin
Honorary Master
- Joined
- Jan 31, 2020
- Messages
- 10,294
- Reaction score
- 10,326
This is PGPNo.
Watch this.
South Africa’s biggest forum. Discuss, discover, and connect with thousands of members.
This is PGPNo.
Watch this.
This is PGP
well of course notIt’s passkeys. Which has nothing to do with 2FA or Authenticator apps.
well of course not
Lol this puts them out of business. Flogging a dead horse.
Much appreciatedNah don’t worry. It’s not easy to understand at first. Hence why I posted the video.
Anyone serious about security would keep using Yubikey.Lol this puts them out of business. Flogging a dead horse.
I always wonder with people that take security to a crazy level, why?Anyone serious about security would keep using Yubikey.
The principles of security haven't changed and "something you have" is still one of the strongest levels of auth N.
In this case they are attempting to use a smart phone as "something you have" device.
But it has updatable software so still at a much lower security tier than a Yubikey which is a hardware smart card with no updateable firmware and is highly resistant to physical cloning (I'd say not possible but that is making a statement that I think can be overcome with enough time and money)
Why do you consider Yubikey crazy?I always wonder with people that take security to a crazy level, why?
Unless that is you don’t know how to keep your passwords safe but otherwise no one can brute force your Google account because they only allow a few tries before you get locked out.
It’s definitely more secure but to my mind its overkill, are you afraid of potential key loggers or similar?Why do you consider Yubikey crazy?
When you need to log into a new device, you type your password, then Google says you need to insert your security token, you do that and touch it, then remove it.
Then you are logged in.
I use a Yubikey for Google and payment because those are the things were I'm concerned about security (if someone got into those they could seriously ruin my life)
Everything else is password manager with randomly generated usernames and passwords (coincidentally if I need to sign into my password manager again I also do Auth N with Yubikey, but that is typically new device and such)
Yubikey has some other connivence things like SSH key storage/SSH key signing and so on but if you don't get the need for Yubikey I'm sure you don't use those.
![]()
My phone getting stolen, cloned SIM card, "hacked", <insert something I haven't thought of here>It’s definitely more secure but to my mind its overkill, are you afraid of potential key loggers or similar?