Conversation

Trash Panda - now diagnosed edition!

Y'all
Why are the yubikey on amazon selling for half the amount of the ones in the yubico store?
The seller seems to be yubico I'm so confused
https://www.amazon.it/Yubico-Autenticazione-Connessione-USB-Certificato/dp/B0BVNPWPCN
2
0
0

@raccoon Usually Amazon keeps those prices fixed to whatever they are being sold at…

1
0
0
@DeltaWye@tiggi.es
So, just to be sure I am not doing something dumb
The one I linked is still the latest version of yubikey and it's an original one, not some fake thing?
2
0
0
@DeltaWye@tiggi.es
Fair no probs, thanks :)
0
0
0

@raccoon @DeltaWye Sure you're comparing the same security key model?

1
0
0

@raccoon @DeltaWye I've seen though that resellers still have better prices :3

1
0
0
@raccoon Why use a yubikey when the fully free/libre nitro key exist ?
1
0
0
@mangeurdenuage@shitposter.world
Because I never heard of it, tell me more
3
0
0
@raccoon @mangeurdenuage don't get the really short one, the pcb you have to touch and that has the hole to attach it to smth so you can carry it breaks easily
1
0
0
@raccoon @mangeurdenuage the one i have and where it happened is the 3a mini
1
0
0
@raccoon @mangeurdenuage i haven't tried the others. Check out what they support and pick the one that supports your usecases
1
0
0
@raccoon @mangeurdenuage ig 3a nfc should be a good starting point if you also want to use it with your phone or non-nfc if just for PCs
2
0
0
@mangeurdenuage @raccoon bewaee they have password management advertised but can only store a handful for some reason
1
0
0
@raccoon
Moon @sun made me discover this, apparently it's the only *key, to have both source code and schematics under GPLv3.
I wish it would be RYF certified tho.
https://en.wikipedia.org/wiki/Nitrokey
https://shop.nitrokey.com/shop/nk3cf-nitrokey-3c-no-nfc-930
https://shop.nitrokey.com/shop/nk3af-nitrokey-3a-no-nfc-934
2
0
0
@snacks @raccoon That's why you combine it with keypassxc.
1
0
1
@mangeurdenuage @raccoon your attacker would need to physically touch it in a specific spot
2
0
0
@mangeurdenuage @raccoon yeah, that's the best way i found to use it to secure passwords
1
0
0
@mangeurdenuage @raccoon it's not like a credit card where you can just hold your phone to the victims pocket
1
0
0
@snacks @raccoon It's basically creates a local 2FA, which renders online 2FA useless.
0
0
1
@snacks @raccoon Show me where on the doll (joke).
0
0
1
@snacks @raccoon I know, you have to "touch" it thus normally the only kind of attack is a time attacks in a very short amount of time, still any wireless transfer in security is always to be considered unsafe.
0
0
0
@mangeurdenuage @raccoon I know some people who work for nitrokey, apparently it's a pretty good product
1
0
1
@mangeurdenuage@shitposter.world
You're gonna hate me but since I will likely need to use it on my mobile I'm gonna probably get it with nfc :P
I will store it in a container that prevent emitting data when not in use.
1
0
0
@raccoon Just get a normal usb-a or usb-c one with a flexible cable extension to avoid break the main connectors, then you add keypassDX for android and you got your 2FA for mobile and it's as practical.
1
0
0
@raccoon
more like an extension cord, but yes in the end it's like a dongle.
https://www.amazon.fr/-/en/YINGAYOU-Extension-Female-Portable-Smartphone/dp/B0FGV158WB

oh wait
I just checked because I haven't yet done test for android
https://support.nitrokey.com/t/nitrokey-3-hmac-keepassdx-android-unlock/7388
https://github.com/Kunzisoft/KeePassDX/issues/304

Apparently Keepass2Android would work but it's dependent on proprietary libraries to work.
https://f-droid.org/forums/topic/keepass2android/

Sorry I though this would already have been implemented for android.

but it would work on desktop.
0
0
0
@sun @raccoon
I wish they would sell kits where you have to solder and flash the components yourself.
0
0
0