5 ms·
The article says that any key will do. Is there any concern with buying a less expensive security key from a less established company, or even a third party sel
by lyrrad 10y ago
The article says that any key will do. Is there any concern with buying a less expensive security key from a less established company, or even a third party seller on a site like Amazon? Could a malicious entity make an intentionally weak security key and sell it? How would such an attack be detectable?
- tptacek 10y agoU2F Yubikeys are so cheap and available (Amazon will ship them Prime) that I'm not sure why you'd waste time looking for alternatives.
- lrvick 10y agoI would stick to things like nitrokeys/yubikeys that have gone through rounds of side-channel attacks, research, and upgrades. The only one I can generally suggest for most people right now, in spite of it being closed, is the yubikey 4. Mostly because it can be configured to require a physical touch for each operation. Something a remote attacker can't do. I started putting some comparisons down here: https://github.com/lrvick/security-token-docs/blob/master/Devices.md https://github.com/lrvick/security-token-docs/blob/master/De...