this post was submitted on 31 Jul 2026
8 points (100.0% liked)

Applied Paranoia

67 readers
8 users here now

Discussions of Paranoia, how to apply it in a digital ecosystem (Security, Privacy, Tools, Applications, Questions)

Rules

  1. Be nice
  2. Stay on topic
  3. Don’t farm rage
  4. Be respectful of others

founded 1 year ago
MODERATORS
 

I like multiple factors. I played with a bunch of different hardware security tokens over time. Fingerprint reading on the token is pretty good, I don't like the idea of typing in a PIN to an untrusted computer to talk to the token. I played with the only key, and it's interesting, but it's been pretty much abandoned by its original developers. So I think it's in dead end. But it did have a physical input keypad on the key. So the PIN didn't have to trust the computer that's nice

What do you use? What is your strategy? Any fun anecdotes?

top 3 comments
sorted by: hot top controversial new old
[–] CompactFlax@discuss.tchncs.de 4 points 1 week ago (1 children)

If I don’t trust the computer with my PIN, I don’t trust it to handle an access token.

[–] jet@hackertalks.com 2 points 1 week ago

the trouble is many tokens the PIN overrides the fingerprint, so giving the pin to a host reduces it from something you have/something you are to just something you have, something you know. And computers are good at knowing things.

[–] jet@hackertalks.com 2 points 1 week ago

i would like to try out the yubikey bio enterprise, but they wont sell it to low volume operations like mine