o da Chave de Seguridade está sendo un pouco aburrido, «en plan» ben  , porque achegueina ao móbil e AuthnKey recoñeceuna por NFC para poder usala (para crear o PIN, alfanumérico), tamén no sentido físico (dentro da funda protectora que trae e a través da cuberta de silicona do móbil; e enchufeina ao pc  e o mesmo: fun á web provedores de correo e dei de alta a chave sen problema como (2FA) segundo factor para autenticarse (@Tutanota non aparece nas listas da fido-alliance, nin nas «integracións» que mostra #token2, pero funcionou perfectamente en  usando #webauthn )

en https://webauthn.io/ podes probar que a configuración do teu sistema e navegador funcionan correctamente, creando unha conta temporal para o caso (que non vale para nada, nin pide datos, e elimínase automáticamente)

na app móbil  de Obanco tamén a pillou correctamente

Decided to give the cross-platform TOTP app from Token2 a go. It's only available from the customer panel, BSL licensed, comes as a zip with Python modules.

To get it to run on Arch Linux you need to update the version of
pyscard in the requirements.txt file to pyscard~=2.3.1, only then will it actually build when you make a venv and run pip install -r requirements.txt.

Other than that it looks like a cool little tool, has both a GUI and a CLI, works fine as far as I can tell. Even lets you require a button press on the key to show an OTP.

#Token2

Terminal Tilt: Upcoming Schedule

Tomorrow: Divoom Pixoo 64 Review.

Monday, Feb 23: Sovereign Authentication (Part 3) – The YubiKey 5 Series Review.

Feb 26: Keychron Q1 V2 – 4 Years Later.

March 2: Sovereign Authentication (Part 4) – Nitrokey 3A NFC Review.

March 5: Epomaker TH99 Pro Review.

March 9: Sovereign Authentication (Part 5) - Token2 Keys Review

https://www.youtube.com/@TerminalTilt

#TerminalTilt #DigitalSovereignty #RightToRepair #Privacy #SelfHosted #YubiKey #Nitrokey #Keychron #Epomaker #Token2 #Divoom #Pixoo64 #DivoomPixoo64 #Zettlr

I have officially deleted my Amazon account and cut ties with their ecosystem entirely. For a long time, the convenience of Prime felt like a necessary evil, especially since they have a warehouse in my city and can do same day shipping. But I can no longer reconcile the big tech giant's behavior with the values I promote at Terminal Tilt. As a privacy advocate and FOSS supporter, continuing to feed the machine feels increasingly hypocritical.

Ethically, their treatment of labor is indefensible. Between the terrible warehouse conditions and the dark patterns designed to make canceling subscriptions nearly impossible, it is clear they view both employees and customers as numbers to be exploited, with contempt. Their anti-competitive practices have done irreparable harm to small businesses and independent creators who are forced to play in a rigged sandbox.

As an FSF and EFF member, I believe privacy is a fundamental right. Amazon's business model relies on massive data harvesting and a huge surveillance network that I simply do not want to be a part of. Deleting my account is my way of reclaiming my digital sovereignty and refusing to let my personal data be a product in their inventory.

The change also affects how I handle Terminal Tilt going forward. I am officially ending the use of Amazon affiliate links for the channel. While the links are a standard revenue stream for most creators, I refuse to track my audience into the Amazon ecosystem just for a small commission. I would rather the channel grow slower and more honestly than profit from a company that actively works against user freedom. Convenience is the enemy of sovereignty.

When I review products now, whether it is the security keys from @nitrokey , @yubico , and Token2 or open source hardware, I will provide links to direct manufacturers or ethical, privacy-respecting retailers instead. Convenience should never be the primary metric for our choices.

If you want to support my work on Linux, privacy, and the #NoAI movement, I encourage you to use my LiberaPay or Ko-Fi links. Supporting creators directly ensures that the content remains independent and free from the influence of the Epstein class and corporate overlords. You can find all my direct support links on my self-hosted Linkstack: https://links.terminaltilt.com

It feels good to be out. It is time to prioritize people and principles over same-day shipping.

#DeleteAmazon #AmazonBoycott #Amazon #Privacy #FOSS #Linux #TerminalTilt #EthicalConsumerism #Ethics #InfoSec #Yubikey #Nitrokey #Token2 #2FA #MFA #Surveillance #SurveillanceCapitalism #DigitalSovereignty #SelfHosting

🚨 New Video: Stop Trusting Google With Your Keys (Part 1 of 5: Sovereign Authentication)

Convenience is the enemy of sovereignty.

You don't own your phone number; you lease it. If you rely on SMS or cloud-synced apps like Google Authenticator, you aren't securing your account. You are handing the keys to a landlord.

In the premiere of this new series, we break down the 4 Tiers of Authentication. We explain why SMS is a disaster, why I deleted Google Authenticator, and why hardware keys are the only way to truly own your access.

100% Human made. #NoAI  

▶️ YouTube: https://www.youtube.com/watch?v=7Y8Q9LnSQxM

📺 PeerTube: https://gnulinux.tube/w/hbNHh7TjUNiCa98waLmHn1

📝 Blog Post: https://www.terminaltilt.com/2026/02/09/stop-trusting-google-with-your-keys/

Support the mission: ☕ https://ko-fi.com/terminaltilt | https://liberapay.com/terminaltilt

#TerminalTilt #NoAI #Security #Privacy #2FA #MFA #Yubikey #Nitrokey #Token2 #FOSS #Linux #Cybersecurity #SelfHosted #Google #DeGoogle #DigitalSovereignty #QueerCreator #DisabledCreator #HumanMade #TechEthics

Stop Trusting Google With Your Keys

YouTube

I wonder, are there any working SSH clients on iOS that can handle ed255519_sk keys?

(That’s the variant where you have a public and private key part however the private key links to a residential key on an external FIDO2 security token. You plug in the token or use NFC, enter the pin and confirm with a touch)

#ssh #fido2 #token2 #iOS #ed25519

I am working on the upcoming security key reviews, including a review of Token2's biometric key, Token2 PIN+Bio3, for a future video.

I know many of you view biometrics as a convenience (or a privacy risk), I want to give Token2 praise for the Bio3.

For users with tremors, Parkinson’s, or cerebral palsy, typing a 20+ character passphrase without a typo can be a physical barrier to security.

A fingerprint sensor isn't lazy, for many it is the only accessible way to be secure.

#Token2 #Accessibility #Security #FIDO2 #Privacy #TerminalTilt #GNULinux #GNU #Linux #FOSS #OpenSource

To contrast Paypal with Cloudflare, this is how you do it correctly.

I was able to enroll all three of my hardware keys ( @nitrokey , @yubico , and Token2) without issue. No one key limits and no being forced into software backups.

When a platform actually respects FIDO2 as a standard, you can have true hardware redundancy.

Of course, I will mention all of this in my upcoming security key series.

#CyberSecurity #FIDO2 #Nitrokey #YubiKey #Token2 #Hardening #TerminalTilt #Cloudflare #Privacy #Security

Is it 2026 or 2006? I just went to harden my PayPal account with my new review units.

Turns out, PayPal still only supports one physical security key. No backups allowed. If you want redundancy, they force you back to TOTP apps or (worse) SMS.

#CyberSecurity #FIDO2 #Yubico #Nitrokey #Privacy #Security #TerminalTilt #FinTechFail #Token2 #Banking #Money

@pink @nitrokey @yubico

UPDATE #2: The Trifecta is Complete!

I’m thrilled to announce that Token2 is joining the upcoming security series!

I am aligning the Token2 review with their core mission: The death of legacy TOTP.

While many users still rely on codes, Token2 is pushing for a 100% phishing resistant future. We will be focusing exclusively on their Open Source, publicly audited FIDO2 stack. This is a massive win for the #FOSS community. Hardware that is both auditable and explicitly designed to move us past insecure, legacy protocols.

The Comparison is now set:

Yubico: The Industry Giant (Closed Source).

Nitrokey: The Open Hardware Veteran.

Token2: The Audited Open FIDO2 Specialist.

Thank you for the boosts!  

#FOSS #CyberSecurity #Token2 #Yubico #NitroKey #Linux #TechReview #Transparency #TerminalTilt