Question for security enthusiasts
Question for security enthusiasts
link to flathub application https://flathub.org/apps/com.yubico.yubioath
Question for security enthusiasts
link to flathub application https://flathub.org/apps/com.yubico.yubioath
You're viewing a single thread.
If you're dedicated to YubiKey, that's fine, but I strongly suggest Open Source and Open Hardware implementations of security keys, such as SoloKey.
SoloKey supports Linux, in that it has been tested on Linux Mint and Manjaro.
https://docs.solokeys.io/udev/
Perhaps their documentation will help you figure out how to get your YubiKey to work?
On Linux, by default USB dongles can't be accessed by users, for security reasons. To allow user access, so-called "udev rules" must be installed.
i think an opensource option is a good idea however the only reason why i want a yubi key is for the yubikey Bio. which has a fingerprint scanner to make sure its really you. i dont know of any other brand that has a finger print scanner for 2FA. if it wasnt for the scanner i would probably go with a solokey
That's fair, I'm personally against biometrics, because if someone ever gets a copy of your fingerprint... it's not a "password" that can be changed. Fingerprints can be faked.
https://www.pcmag.com/news/hacking-fingerprints-is-actually-pretty-easy-and-cheap
Once again, personal opinion. You gotta do what works for you.
I'm hoping maybe the link I sent might have some info on getting it set up properly on NixOS. Maybe it just needs those udev rules installed first?
yeah, i get the disadvantages of bio-metrics, however i kinda thought about worse case. lets say i have my yubi key and i misplace it, a bad actor gets a hold of my key and uses it to unlock my accounts. however if i got the yubikey with biometics if someone got there hands on it. its a paperweight with out my fingerprint. so its not that i think that bio-metrics is super secure but its added protection against theft. and a very interesting article. and i will try to setup udev rules as the guide you have sent may solve my problem, also thanks for the advise!!
The Yubikey is just one factor. The attacker still need to know your account and password to get hold of your account. However, if you're using passwordless login, bio is a sensible choice.
Nice, I sincerely hope it helps!
I aim for "Something I am, something I have, something I know"
Hate myself for it most of the time but it's secure 😂
i did find FEITIAN BioPass FIDO2 which still is not open sourced but is an alternative for a yubikey, there is no app tho