Login Llama
2.7K posts

Login Llama
@LoginLlama
I promise to take responsibility for securing my Google, Facebook, Dropbox and GitHub accounts with FIDO until my corporate IT provides it for everyone
Calama, Chile Katılım Eylül 2017
69 Takip Edilen830 Takipçiler

This is good, however I would still want a non Google stored passkey as a way back into my Google account protected with advanced protection.
forbes.com/sites/daveywin…
English

Finally a way to secure a Google account without having to have SMS.
theverge.com/2024/5/6/24150…
English

LastPass Master Password Threat Confirmed—Don’t Press 1 Or 2 forbes.com/sites/daveywin…
English
Login Llama retweetledi

Introducing: YubiKeys for Pets 🐶🐱
You can now enjoy peace of mind with FIDO for Fido - because it can be ruff out there!
#AprilFoolsDay
English

Glad to see them supporting passkeys. There is a bit of posturing going on amongst the password managers. Platforms and the existing Fido community have put in a lot of work to open up to third party credential providers beyond security keys.
9to5mac.com/2024/03/21/pro…
English

Or you could just use passkeys. He mentions that at the very end. I have been warning about this sort of attack for years.
youtu.be/qItXM_oPmbA?si…

YouTube
English

Google partners on passkey upgrades, will drop Pixel exclusivity 9to5google.com/2024/01/30/goo…
English

We keep saying SMS is a insecure form of second factor. Incidents like this help make the point.
techcrunch.com/2024/02/29/lea…
English
Login Llama retweetledi

Still need more convincing to adopt #passkeys? dvuln.com/blog/poor-mans…
English

@ygini @Serianox_ I will see if I can get someone to open an issue for it.
English

@LoginLlama @Serianox_ I actually wonder how this idea / needs could be submitted to the WebAuthN workgroup.
Could be a really powerful addition for enterprise needs.
English

With WebAuthN is there a way for the website to be aware of a physical token removal? To automatically logout a user authenticated with a Yubikey or something equivalent
@LoginLlama or @Serianox_ any idea?
English

@ygini @Serianox_ I understand. It would be nice if at least in the enterprise use case the webauthn could provide a key removal signal. I don’t think we would ever get that for consumers.
English

@LoginLlama @Serianox_ I which I could avoid smart card. The enrollment part is a mess… I will look at web smart card by curiosity.
Thanks!
English