I am thinking about buying a pair of physical 2FA keys to protect my password manager and sensitive accounts. Which brand and model do you suggest?

If a model with open source firmware doesn’t come with big drawbacks, I’d prefer it, because I may learn from the source code and even contribute to it.

NFC is not necessary, and the keys should be USB-A. A fingerprint reader is welcome if the price doesn’t increase too much.

Thank you all in advance.

Matt
link
fedilink
25d

I use Yubikey 5C NFC. You can get it for ~29€ last time I checked.

https://onlykey.io/

6 FIDO keys in one.

sparkle_matrix_x0x
creator
link
fedilink
15d

That’s cool, strange I didn’t stumble over it when I was searching for these keys. Have you got one? Is it durable?

I got one years ago. Used it for quite a bit. Worked great, but I stopped using it when my daily computer didn’t have a USB-A port any more.

You do have to remember what each numbered button is for.

I use Yubikey Bio and NitroKeys.

Ghoelian
link
fedilink
26d

I have a nitrokey which works great. Only downside is the software isn’t as user friendly, you need to set it up using the cli.

sparkle_matrix_x0x
creator
link
fedilink
2
edit-2
6d

I am fine with a cli, I use arch btw.

How long have you had your nitrokey? Others are concerned about their durability…

Have you ever had a yubikey?

Ghoelian
link
fedilink
36d

I’ve only had the nitrokey for a few months, so can’t comment on the durability yet.

I did have a yubikey before. My experience with them wasn’t great, I often had to re-plug in the key because the touch to activate thing was pretty unreliable for me, often just not responding to touch at all.

Though ultimately the reason I chose nitrokey is because I was just looking for a European alternative.

Your only “good” option is yubikey. They’ve been around comparatively forever, have all the problems worked out and make durable hardware. All that matters because you don’t want to get something from a company that goes under in a few years and leaves you high and dry and you don’t want the dongle to break because that’s your authentication, now you’re locked out of your shit.

I recommend against getting some doodad with a biometric reader. You’re adding complexity, attack vectors and not getting much out of it plus you’re locking yourself out of deniability and the possibility of handing a trusted person your dongle, telling them your password and having them act in your stead.

sparkle_matrix_x0x
creator
link
fedilink
26d

You’re right about the FP reader, I didn’t think about that before

turtl
link
fedilink
56d

Why do folks seem to prefer Yubikey over alternatives like Nitrokey or Token2?

So far nobody provided a good answer (if I missed it, I apologized, please do share) so I’m going to assume it’s the typical “Nobody ever get fired for buying from IBM” mindset, namely rely on what is the most popular, confirm it works well while ignoring viable alternatives IMHO, e.g NitroKey.

Godort
link
fedilink
25d

I’m going to assume it’s the typical “Nobody ever get fired for buying from IBM” mindset

That’s pretty much it exactly. Yubico has the required features, are widely supported, and are widely used. They have a track record of reliability.

Other viable alternatives definitely exist, but they don’t have the same real-world penetration. The disadvantage with that is if you run into a platform-specific issue, finding someone who has had the same issue before and posted the solution somewhere becomes far less likely.

Longevity (mine is about 15 years old)

sparkle_matrix_x0x
creator
link
fedilink
16d

That the same thing I asked myself…

Do you mean TOTP? FIDO? Or what? FOSS ones exist but they might not do exactly the right thing. I’ve had some ideas for self-built too. What would you do on the host interface side? Wouldn’t you want the host to not have the secret?

It’s an interesting question.

sparkle_matrix_x0x
creator
link
fedilink
26d

I would use it for FIDO2 authentication

Godort
link
fedilink
5
edit-2
5d

Yubico is industry standard for a reason. The current 5 model will have all the features you need and they are basically indestructible.

Yubico keys. Never had an issue after years of dangling on my keychain. They get replaced with upgrades to the key before they can break.

monovergent
link
fedilink
66d

The firmware isn’t open source and I only chose it for the employee discount, but the blue Yubico security key has held up well over hundreds of uses and several years jingling around in my keychain.

Was going to say Yubikey also. I don’t like that it’s not open, but I’ve had open firmware keys before and they broke after several months of use. Meanwhile, my Yubikey has been kicking it on my keychain for almost fifteen years without any signs of wear, other than the paint scraping off of it.

Em Adespoton
link
fedilink
26d

The one I have on me. Which happens to be my Yubikey currently.

Create a post

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

  • Posting a link to a website containing tracking isn’t great, if contents of the website are behind a paywall maybe copy them into the post
  • Don’t promote proprietary software
  • Try to keep things on topic
  • If you have a question, please try searching for previous discussions, maybe it has already been answered
  • Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
  • Be nice :)

Related communities

much thanks to @gary_host_laptop for the logo design :)

  • 0 users online
  • 108 users / day
  • 435 users / week
  • 1.32K users / month
  • 4.54K users / 6 months
  • 1 subscriber
  • 4.35K Posts
  • 110K Comments
  • Modlog