That's a Google (design) feature, in fact the majority of phone models have this "feature".
These Nitro dudes can just do it for you before shipping it to you - still need to open the phone to reconnect/reinstall it.
I mean a whole lot of people don't know how to do that, or are too busy to. I guess there are other alternatives but if it lives up to what it says on the box I can see someone finding value in it. Though all it says on the box is that you can dispose of it in a dedicated landfill after use or something so YMMV I guess
It can be read. But you also have to physically tap the security key to do anything. If they don't get access to your security key the PIN alone is useless.
Tbh, I find Nitrokey over priced. Token2 is technologically superior (when you only look at the core passkey field) and cheaper - and at least is swiss made. especially as a sensible policy requires more than one token.
It's a security key meant to replace passwords with passkeys, but it does some other things as well.
The main thing which makes them secure is no one can export, read, copy the keys that are inside it, even if the PC is infected.
I also store a GPG key to encrypt / decrypt some sensitive stuff and a SSH key.
You can also use them as OTP replacement instead of using apps like google authenticator, aegis or whatever your choice is. It also makes it more secure. Though I don't think I will be doing that.
Main thing I bought it was for GPG and to secure my password manager. The good thing is because you have a security key your PIN can be significantly shorter than a password managers password and you don't sacrifice security. Nitrokey, for example, allows 8 tries to enter the FIDO2 (passkey) PIN. After 8 incorrect attempts it will block it and you will need to do a reset. Also people have to physically have your security key to even enter the PIN. So I simply have a 6 digit PIN code.
26 Comments
espentan@lemmy.world · 38 pts · 124d
It's a little funny, with the slogan "fck big tech", that both Amazon and Google are on the customer list.
Evil_Shrubbery@thelemmy.club · 6 pts · 123d
They are also a costumer of theirs, they are supporting Google by reselling their phones.
realitaetsverlust@piefed.zip · 11 pts · 124d
Goddamn those are some expensive fucking devices holy shit. 1500 bucks for a 256GB storage smartphone is insanity.
unglueclass23@programming.dev · 7 pts · 124d
Not gonna lie I have no clue why they charge +500 eur for a re-branded Google Pixel. Just cuz they installed GrapheneOS?
realitaetsverlust@piefed.zip · 1 pts · 124d
It doesn't seem to be a re-branded pixel, as it does have a few cool features, like disconnectable microphone and stuff. Still not worth it imo.
Evil_Shrubbery@thelemmy.club · 1 pts · 123d
That's a Google (design) feature, in fact the majority of phone models have this "feature".
These Nitro dudes can just do it for you before shipping it to you - still need to open the phone to reconnect/reinstall it.
tomiant@piefed.social · 1 pts · 123d
I mean a whole lot of people don't know how to do that, or are too busy to. I guess there are other alternatives but if it lives up to what it says on the box I can see someone finding value in it. Though all it says on the box is that you can dispose of it in a dedicated landfill after use or something so YMMV I guess
Evil_Shrubbery@thelemmy.club · 2 pts · 123d
Just add a thousand monies to get the TB - that is way cheaper than four 256GB models!!
akunohana@piefed.blahaj.zone · 6 pts · 124d
Sweet! I myself have been rocking my Yubikey for six years now. 😃
Dyskolos@lemmy.zip · 6 pts · 123d
Call me nitpicky, but couldn't it have been a .de domain 😁
LeTak@feddit.org · 5 pts · 124d
Nice, I also have some. Sadly one of them died.
tooks@lemmy.world · 4 pts · 124d
Love the idea, but I was wondering about their lifespan. Or misplacing/losing it.
LeTak@feddit.org · 3 pts · 124d
I like the software. It was somewhat easier than yubikey.
beeng@discuss.tchncs.de · 4 pts · 123d
Its to store passkeys in a secure enclave if I get it right? With finger print?
glitch1985@lemmy.world · 5 pts · 123d
Your anus print is also unique. Use that information how you want.
Zozano@aussie.zone · 8 pts · 123d
With the frequency my haemorrhoid's flare up, my anal print might vary from day to day.
glitch1985@lemmy.world · 2 pts · 123d
I appreciate that nugget of information.
Zozano@aussie.zone · 1 pts · 123d
My haemorrhoids appreciate nuggets too, as opposed to slurry.
unglueclass23@programming.dev · 1 pts · 122d
It doesn't come with a fingerprint scanner. Just have to tap to confirm the log in. Obviously , you set a PIN as well.
beeng@discuss.tchncs.de · 1 pts · 122d
Enter the Pin on your PC? Doesn't that mean it could be read? Crypto safes do pin/unlock on device so just curious
unglueclass23@programming.dev · 1 pts · 122d
It can be read. But you also have to physically tap the security key to do anything. If they don't get access to your security key the PIN alone is useless.
philpo@feddit.org · 3 pts · 123d
Tbh, I find Nitrokey over priced. Token2 is technologically superior (when you only look at the core passkey field) and cheaper - and at least is swiss made. especially as a sensible policy requires more than one token.
rustydrd@sh.itjust.works · 3 pts · 124d
Nice, I got one of these too! Using it mainly for 2FA at my workplace, and it works really well. Easy to set up, even for a security noob like me.
fxdave@lemmy.ml · 3 pts · 122d
The questions everybody's looking for in the comments: What's this? Why aren't you using a password?
unglueclass23@programming.dev · 2 pts · 122d
It's a security key meant to replace passwords with passkeys, but it does some other things as well.
The main thing which makes them secure is no one can export, read, copy the keys that are inside it, even if the PC is infected.
I also store a GPG key to encrypt / decrypt some sensitive stuff and a SSH key.
You can also use them as OTP replacement instead of using apps like google authenticator, aegis or whatever your choice is. It also makes it more secure. Though I don't think I will be doing that.
Main thing I bought it was for GPG and to secure my password manager. The good thing is because you have a security key your PIN can be significantly shorter than a password managers password and you don't sacrifice security. Nitrokey, for example, allows 8 tries to enter the FIDO2 (passkey) PIN. After 8 incorrect attempts it will block it and you will need to do a reset. Also people have to physically have your security key to even enter the PIN. So I simply have a 6 digit PIN code.
tomiant@piefed.social · 1 pts · 123d
Diddlydee@feddit.uk · 1 pts · 124d
Fuck big tech, pay us wildly over the odds instead.