Skip to main content

Questions tagged [yubikey]

YubiKey is an USB authentication key developed by Yubico.

0 votes
1 answer
117 views

I’m a beginner but I’ve been reading, watching videos, and chatting with an assistant to build a stronger workflow for online security (logins + recovery) and I am planning on getting a yubikey. One ...
nostaller's user avatar
3 votes
1 answer
183 views

A few years ago, I set up my Yubikey with PGP by following Dr.Duhs Yubikey Guide. I created an offline Certify key / Master key on a live usb distro, and then created the corresponding sub keys (S,A,E)...
DanRan's user avatar
  • 141
3 votes
1 answer
845 views

Is an id_ed25519_sk cryptographically secure without a password? I'm currently experimenting with a yubikey SSH identity. Following instructions to generate an SSH key: sudo ssh-keygen -t ed25519-sk -...
Philip Couling's user avatar
1 vote
0 answers
88 views

One of the benefits of using OpenPGP authentication subkeys instead of arbitrarily created SSH keyfiles, is key expiration and revocation. While there is plenty of documentation on how to use OpenPGP ...
awolf's user avatar
  • 11
0 votes
0 answers
140 views

I'm trying to securely encrypt and decrypt data using a biometric info, i.e. a fingerprint, on a Raspberry PI. From my prior research, I have found that I need an HSM, since fingerprints cannot be ...
Ezlanding's user avatar
  • 125
0 votes
1 answer
151 views

Yubico PAM module requires one to specify the id(API client ID) parameter obtained from Yubico API key signup page. For example: auth sufficient pam_yubico.so id=1234 authfile=/etc/yubikey_mappings ...
Martin's user avatar
  • 441
0 votes
0 answers
411 views

Whatsapp is rolling out passkeys. I don't think backing up passkeys in a password manager is a good idea. I'd like to have device bound passkeys but they only allow me to create one. How should I be ...
Gatonito's user avatar
  • 375
18 votes
5 answers
7k views

It is typically recommended to enable 2FA wherever possible. Moreover, it is typically recommended to enable not just any 2FA method, but Yubikeys in particular. Yubikeys are considered to be the ...
gaazkam's user avatar
  • 6,851
0 votes
0 answers
164 views

I'd like to use YubiKey Bio for SSH-logins. I'm wondering how often I have to show my fingerprint for authentication when I start new sessions. What's the interval? If I start a new session every 5 ...
Kevin Meier's user avatar
2 votes
0 answers
429 views

Is the 32 OATH QR code account limit on Yubikeys due to a storage constraint? Because the Yubikey 5 series has been out for a few years now it'd be amazing if there is a new version released soon with ...
adamhurwitz.eth's user avatar
0 votes
1 answer
722 views

I wonder if the NSA can force Yubico (or their secure element chip supplier), a US company located in Palo Alto, California, to hand over the private keys stored in the secure element of the yubikey ...
AND's user avatar
  • 11
0 votes
1 answer
201 views

How are the above devices built and what is the mechanism that seals them off from giving out private keys? Are the sign/decrypt operations somehow soddered into their hardware, is it a tiny piece of ...
Cigarette Smoking Man's user avatar
3 votes
1 answer
1k views

I was looking at YubiKeys and noticed that they sell FIPS certified keys alongside non-FIPS certified keys. Both seem to have the same feature sets, but the FIPS certified keys are more expensive. ...
Unknown's user avatar
  • 195
6 votes
1 answer
1k views

My understanding is that an ED25519-sk SSH key generated by OpenSSH generates a private key stub that lives on your host machine. This stub is just a reference to the actual private key that lives on ...
angryserver's user avatar
0 votes
1 answer
244 views

I bought a new Yubikey, and am currently setting it up to use on my desktop PC. Previously the PC was secured with password only, and I'd like to use the Yubikey as an alternative: instead of using ...
Danya02's user avatar
  • 508

15 30 50 per page
1
2 3 4 5
13