Ancestors

Toot

Written by release_candidate on 2024-12-16 at 20:57

So, it has been like three months using FIDO/U2F keys instead of passwords. Both in my NetBSD and Arch systems.

I use a "medium" quality password to decrypt the filesystems and other one to decrypt the password manager. And that's it.

No password to log-in, to unlock screen, to run doas/sudo, etc. Just this little penguin and press its button.

Also, I'm using this as 2FA for all websites that support it. Lemmy doesn't. It's the only place where I don't use it, yet.

Because U2F uses the domain name, this is a strong protection against phishing. A similar domain may trick my eyes, but not the key.

I'm very bad at memorizing passwords, and worse at typing them. Unlocking the screen without typing my password like 3 times is a bless.

The problems: if my laptop is decrypted anybody with this penguin is root. It's kinda my Horcrux. Also, I need a second one stored safely as a backup.

So I officially have two horcruxes. Destroy both and I can't log-in anywhere.

[#]fido #u2f #infosec #NetBSD #arch #keepass #password #horcrux

=> View attached media

=> More informations about this toot | More toots from release_candidate@bsd.cafe

Descendants

Proxy Information
Original URL
gemini://mastogem.picasoft.net/thread/113664501255058007
Status Code
Success (20)
Meta
text/gemini
Capsule Response Time
237.773588 milliseconds
Gemini-to-HTML Time
0.855144 milliseconds

This content has been proxied by September (ba2dc).