3 ms·
Why everyone working with the government doesn't use hardware keys without passwords so that fishing is useless?
by codedokode 1y ago
Why everyone working with the government doesn't use hardware keys without passwords so that fishing is useless?
- bornfreddy 1y agoBecause hardware keys are so 2000 - we have apps now. With Play Protect Premium Enterprise to make sure the phone is secure. /s
- ac29 1y agoI know some people in the US government who definitely need a hardware key to access computing resources including email. They work for the Dept of the Interior on science stuff, nothing related to national security or otherwise sensitive info. They mentioned this was a pain in the ass, and a very weird restriction since technically any member of the public can ask for a copy of their emails via FOIA.
- sulandor 1y agosounds like the primary goal was better attestation
- alt227 1y agoSurely people can still phish for the user to insert their hardware key to approve something malicious?
- deleted 1y ago[deleted]
- kbrkbr 1y agoWhat is phishing resistant MFA? - https://www.sans.org/blog/what-is-phishing-resistant-mfa https://www.sans.org/blog/what-is-phishing-resistant-mfa
- alt227 1y agoExactly. 'Resistant' not 'impenitrable'. The article itself says that 100% phishing resistance is impossible. So I stand by my arguement that if you give an idiot a Yubikey, it still doesnt save them from themselves. >Does this technology eliminate all risk? No. As this becomes widely deployed new attacks will be developed, but it will be MUCH harder for the cyber attacker. > FIDO is extremely resistant to phishing attacks but adopting FIDO does not mean your organization is secure against phishing.
- codedokode 1y agoHardware keys (unlike humans) usually check page URL and do not send the data stored by another domain.
- mr_toad 1y agoA lot of legacy tech doesn’t support hardware keys. Last government job I had still ran an old SVN server with unencrypted username/password auth (relying on the VPN for security).