• fxdave@lemmy.ml
    link
    fedilink
    English
    arrow-up
    3
    ·
    1 day ago

    The questions everybody’s looking for in the comments: What’s this? Why aren’t you using a password?

    • unglueclass23@programming.devOP
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 day ago

      It’s a security key meant to replace passwords with passkeys, but it does some other things as well.

      The main thing which makes them secure is no one can export, read, copy the keys that are inside it, even if the PC is infected.

      I also store a GPG key to encrypt / decrypt some sensitive stuff and a SSH key.

      You can also use them as OTP replacement instead of using apps like google authenticator, aegis or whatever your choice is. It also makes it more secure. Though I don’t think I will be doing that.

      Main thing I bought it was for GPG and to secure my password manager. The good thing is because you have a security key your PIN can be significantly shorter than a password managers password and you don’t sacrifice security. Nitrokey, for example, allows 8 tries to enter the FIDO2 (passkey) PIN. After 8 incorrect attempts it will block it and you will need to do a reset. Also people have to physically have your security key to even enter the PIN. So I simply have a 6 digit PIN code.

  • philpo@feddit.org
    link
    fedilink
    English
    arrow-up
    3
    ·
    2 days ago

    Tbh, I find Nitrokey over priced. Token2 is technologically superior (when you only look at the core passkey field) and cheaper - and at least is swiss made. especially as a sensible policy requires more than one token.

  • espentan@lemmy.world
    link
    fedilink
    English
    arrow-up
    31
    ·
    3 days ago

    It’s a little funny, with the slogan “fck big tech”, that both Amazon and Google are on the customer list.

      • tomiant@piefed.social
        link
        fedilink
        English
        arrow-up
        1
        ·
        edit-2
        1 day ago

        I mean a whole lot of people don’t know how to do that, or are too busy to. I guess there are other alternatives but if it lives up to what it says on the box I can see someone finding value in it. Though all it says on the box is that you can dispose of it in a dedicated landfill after use or something so YMMV I guess

      • realitaetsverlust@piefed.zip
        link
        fedilink
        English
        arrow-up
        1
        ·
        3 days ago

        It doesn’t seem to be a re-branded pixel, as it does have a few cool features, like disconnectable microphone and stuff. Still not worth it imo.

        • Evil_Shrubbery@thelemmy.club
          link
          fedilink
          English
          arrow-up
          1
          ·
          edit-2
          2 days ago

          disconnectable

          That’s a Google (design) feature, in fact the majority of phone models have this “feature”.
          These Nitro dudes can just do it for you before shipping it to you - still need to open the phone to reconnect/reinstall it.

  • rustydrd@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    3
    ·
    edit-2
    3 days ago

    Nice, I got one of these too! Using it mainly for 2FA at my workplace, and it works really well. Easy to set up, even for a security noob like me.