this post was submitted on 21 Mar 2024
111 points (98.3% liked)
Privacy
31935 readers
764 users here now
A place to discuss privacy and freedom in the digital world.
Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.
In this community everyone is welcome to post links and discuss topics related to privacy.
Some Rules
- Posting a link to a website containing tracking isn't great, if contents of the website are behind a paywall maybe copy them into the post
- Don't promote proprietary software
- Try to keep things on topic
- If you have a question, please try searching for previous discussions, maybe it has already been answered
- Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
- Be nice :)
Related communities
Chat rooms
-
[Matrix/Element]Dead
much thanks to @gary_host_laptop for the logo design :)
founded 5 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
This is an interesting piece of kit, though I'm curious who the target market really is? Frankly I would be more comfortable regularly rotating my hardware security key's password than I would be manually keying in my 2nd factors pin every time I need to use FIDO2 or TOTP. This would almost appear to be an excessive amount of security for me as an infosec professional which honestly makes me suspect it's targeted towards a paranoid audience. Not that this wouldn't have it's applications. As a backup security key to be stored in a secure location this is definitely intriguing, but I can't imagine using it on a daily basis.
I think “unnecessarily over-the-top” is a key demographic in every market. Not a large one, but definitely present.
Manually keying in the pin is only needed when plugging in the device. Challenges for TOTP, FIDO2, etc. are a configuration option, and are only 3 digits if enabled (press any button if disabled).
As for "excessive amount of security", security as an absolute measure isn't a great way to think about it. Use case and threat model are more apt.
For use case, I'll point out it's also a PGP and SSH device, where there is no third party server applying the first factor (something you know) and needs to apply both factors on device.
For threat model, I'll give the example of an activist who is arrested. If their e-mail provider is in the country, they can compel the provider to give them access, allowing them to reset passwords on other more secure services hosted outside the country. The police now have the second factor (something you have), but can't use it because it's locked.
If your usecase and threat model don't require the pinpad, Onlykey Duo is worth a look. No pin, USB A or C, and still gives you 6 slots to support any combination of Fido2, TOTP, SSH, PGP, and password storage.
I have one and I would not consider myself paranoid. I go to school part time and have to login with different accounts on rotating computers. It is nice to have a password manager I can plug into the PC instead of typing it off of my phone or having to memorize it.