Ich habe für meine Serie »CachyOS härten« eine kurze Anleitung geschrieben, wie man auf #CachyOS das #Login sowie #sudo und #su und #KDE (eher improvisiert) mit einem #Fido2 Token absichert. Getestet mit #yubico #yubikey #nitrokey, #token2 r3 und #thetis via #pam und #pam_u2f

Damit kann man dann #mfa mit 3 Faktoren (Token: PIN und Besitz sowie das normale Passwort) umsetzen.

Obacht: man kann sich beim nachbauen schnell mal komplett aussperren, also die beschriebenen Vorsichtsmaßnahmen beachten.

https://cryptomancer.de/posts/20260523-sudoyubikey/

Falls jemand weiß wie man KDE/SDDM besser mit pam_u2f absichert, immer her mit den Ideen.

@Cloudsincoffee

do they work on Linux for LUKS etc. - can you use the same package yubikey-luks? I'm currently using Yubikey, but always open for change, if it is not too difficult.

#Yubikey #Token2 #LUKS #Linux #FIDO2 #MFA

@bazurk I got a couple of #token2 security keys. They are much cheaper than #Yubikey . I have been happy with them.
https://www.token2.com/
TOKEN2 Sàrl is a Swiss cybersecurity company specialized in the area of multifactor authentication. We are a FIDO Alliance member.

OTP Token, TOTP token, Replace your mobile authenticator with secure hardware OTP token! Easily programmed via NFC. Designed to use with Google, Facebook, Dropbox, GitHub, Wordpress, Office 365, Azure MFA etc.

Xa temos en  dispoñible a versión 1.2.1 de #AuthnKey (provedor de claves de paso e chaves de seguridade para  ). É a primeira co idioma #galego incluído 

Polo mesmo prezo 💶💶 traducín Open Passkey Authenticator (a día de hoxe aínda non se publicou en galego).

#android #passkey #securitykey #authenticator #token2 #yubikey et al.

Seeing the latest video hit #1 in the studio dashboard is a great reminder of why I started Terminal Tilt.

780 views in less than 7 hours on a video about hardware security keys? You all prove there’s a massive hunger for privacy and right-to-repair content.

Huge thank you to everyone who watched and shared!

If you haven't watched it yet, its available here: https://www.youtube.com/watch?v=lQlN84gEb9c

#DigitalSovereignty #Privacy #OpSec #RightToRepair #OpenSource #Token2 #Yubikey #Nitrokey #TerminalTIlt

🚨 New Video: Protecting You From Yourself - The Token2 Review

We have looked at the industry standard (YubiKey) and the philosophical idealist (Nitrokey). Today, we’re looking at the aggressor: Token2.

The PIN+ Dual Release 3.3 and the Bio3 come in at nearly half the price of the competition, but there is a catch. This Swiss company doesn't care about convenience; they care about correctness. From hardware-enforced complex PINs to a literal war on legacy TOTP codes, Token2 assumes your ego is your biggest vulnerability.

Is this cynical, locked-down approach exactly what we need for true digital sovereignty, or is the clunky user experience a dealbreaker? Let's find out if this is the ultimate punk rock choice for your threat model.

Part 5 of the Sovereign Authentication series.

100% human made. #NoAI 

▶️ YouTube: https://www.youtube.com/watch?v=lQlN84gEb9c
📺 PeerTube: https://gnulinux.tube/w/fZbyKea1b6QJVQoFE4oQso

💬 Join our sovereign community on Stoat: https://stt.gg/GgB6HBTv
☕ Support the mission: https://liberapay.com/terminaltilt
🤝 Become a channel member: https://www.youtube.com/@TerminalTilt/join

#TerminalTilt #NoAI #Privacy #Security #PasswordManager #Token2 #Nitrokey #Yubikey #Yubico #FOSS #OpenSource #Linux #Cybersecurity #SelfHosted #DeGoogle #DigitalSovereignty #QueerCreator #DisabledCreator #HumanMade #TechEthics

Protecting You From Yourself - The Token2 Review

YouTube

o da Chave de Seguridade está sendo un pouco aburrido, «en plan» ben  , porque achegueina ao móbil e AuthnKey recoñeceuna por NFC para poder usala (para crear o PIN, alfanumérico), tamén no sentido físico (dentro da funda protectora que trae e a través da cuberta de silicona do móbil; e enchufeina ao pc  e o mesmo: fun á web provedores de correo e dei de alta a chave sen problema como (2FA) segundo factor para autenticarse (@Tutanota non aparece nas listas da fido-alliance, nin nas «integracións» que mostra #token2, pero funcionou perfectamente en  usando #webauthn )

en https://webauthn.io/ podes probar que a configuración do teu sistema e navegador funcionan correctamente, creando unha conta temporal para o caso (que non vale para nada, nin pide datos, e elimínase automáticamente)

na app móbil  de Obanco tamén a pillou correctamente

Decided to give the cross-platform TOTP app from Token2 a go. It's only available from the customer panel, BSL licensed, comes as a zip with Python modules.

To get it to run on Arch Linux you need to update the version of
pyscard in the requirements.txt file to pyscard~=2.3.1, only then will it actually build when you make a venv and run pip install -r requirements.txt.

Other than that it looks like a cool little tool, has both a GUI and a CLI, works fine as far as I can tell. Even lets you require a button press on the key to show an OTP.

#Token2

Terminal Tilt: Upcoming Schedule

Tomorrow: Divoom Pixoo 64 Review.

Monday, Feb 23: Sovereign Authentication (Part 3) – The YubiKey 5 Series Review.

Feb 26: Keychron Q1 V2 – 4 Years Later.

March 2: Sovereign Authentication (Part 4) – Nitrokey 3A NFC Review.

March 5: Epomaker TH99 Pro Review.

March 9: Sovereign Authentication (Part 5) - Token2 Keys Review

https://www.youtube.com/@TerminalTilt

#TerminalTilt #DigitalSovereignty #RightToRepair #Privacy #SelfHosted #YubiKey #Nitrokey #Keychron #Epomaker #Token2 #Divoom #Pixoo64 #DivoomPixoo64 #Zettlr

I have officially deleted my Amazon account and cut ties with their ecosystem entirely. For a long time, the convenience of Prime felt like a necessary evil, especially since they have a warehouse in my city and can do same day shipping. But I can no longer reconcile the big tech giant's behavior with the values I promote at Terminal Tilt. As a privacy advocate and FOSS supporter, continuing to feed the machine feels increasingly hypocritical.

Ethically, their treatment of labor is indefensible. Between the terrible warehouse conditions and the dark patterns designed to make canceling subscriptions nearly impossible, it is clear they view both employees and customers as numbers to be exploited, with contempt. Their anti-competitive practices have done irreparable harm to small businesses and independent creators who are forced to play in a rigged sandbox.

As an FSF and EFF member, I believe privacy is a fundamental right. Amazon's business model relies on massive data harvesting and a huge surveillance network that I simply do not want to be a part of. Deleting my account is my way of reclaiming my digital sovereignty and refusing to let my personal data be a product in their inventory.

The change also affects how I handle Terminal Tilt going forward. I am officially ending the use of Amazon affiliate links for the channel. While the links are a standard revenue stream for most creators, I refuse to track my audience into the Amazon ecosystem just for a small commission. I would rather the channel grow slower and more honestly than profit from a company that actively works against user freedom. Convenience is the enemy of sovereignty.

When I review products now, whether it is the security keys from @nitrokey , @yubico , and Token2 or open source hardware, I will provide links to direct manufacturers or ethical, privacy-respecting retailers instead. Convenience should never be the primary metric for our choices.

If you want to support my work on Linux, privacy, and the #NoAI movement, I encourage you to use my LiberaPay or Ko-Fi links. Supporting creators directly ensures that the content remains independent and free from the influence of the Epstein class and corporate overlords. You can find all my direct support links on my self-hosted Linkstack: https://links.terminaltilt.com

It feels good to be out. It is time to prioritize people and principles over same-day shipping.

#DeleteAmazon #AmazonBoycott #Amazon #Privacy #FOSS #Linux #TerminalTilt #EthicalConsumerism #Ethics #InfoSec #Yubikey #Nitrokey #Token2 #2FA #MFA #Surveillance #SurveillanceCapitalism #DigitalSovereignty #SelfHosting