6 ms·
This low-cost device may be the world’s best hope against account takeovers
- amelius 10y agoI'd be interested to hear how people on HN currently secure their SSH sessions with two-factor authentication.
- typicalrunt 10y agoDuo: https://duo.com https://duo.com Super easy to setup and use. About $1/user/month, so fairly cheap.
- amelius 10y agoDoes it allow to do "nested" logins? E.g., first login from machine A to machine B, then login from machine B to machine C, while the security token is on machine A?
- brycehamrick 10y agoI use Authy for this. If it's all you use Authy for you can easily get away with just using their free tier. https://github.com/authy/authy-ssh https://github.com/authy/authy-ssh
- vageli 10y agoGoogle 2fa is easy to set up as a PAM module.
- h4waii 10y agoPAM + OTP. See the Arch Wiki [0], though it's applicable on almost every single distribution. You can use keys for known devices, and use passphrase and OTP for unknown devices if you need to SSH in a bind. 0. https://wiki.archlinux.org/index.php/Google_Authenticator https://wiki.archlinux.org/index.php/Google_Authenticator
- crdoconnor 10y agoThe difficult question regarding two factor authentication is "what do you do if you lose the second factor?" The answer to that question can often range all the way from "your account is lost forever" to "you have to go through a whirlwind of bureaucratic pain" to "the alternative method of entry is easy, hassle free, and how your account will end up compromised."
- skookum 10y agoYubico's answer to this is to own & register two of them against the account/software they are being used as the 2nd factor for. Some accounts also offer something short of the whirlwind but not as socially engineerable as the obvious easy, hassle free methods - for example Google issues backup codes for signing into the account when you lose all your means of 2FA.
- chrismeller 10y agoOut of curiosity, do you actually have your backup codes somewhere? I know I did at some point, but the things you don't use, you lose...
- brudgers 10y agoPlugging a device into a USB port was the method by which Stuxnet was deployed.
- plg 10y agoNew MBP laptops have no compatible USB slots Another dongle
- plg 10y agoWhat about Apple Watch for 2FA
- h4waii 10y agoUnfortunately Apple Watch and Android Wear don't seem to have an offline H/TOTP generator. Pebble is the only real wearable that does have an open source on-device OTP generator => https://github.com/JumpMaster/QuickAuth https://github.com/JumpMaster/QuickAuth and it's one of the main reasons I've stuck with Pebble.
- smgoller 10y agoAuthenticator Plus (https://www.authenticatorplus.com/ https://www.authenticatorplus.com/) has both apple watch and android wear support.