My trusted defender - Yubikey

in Proof of Brain3 years ago

Whenever I get into conversation with somebody about Internet dangers, about security and protection, at some point I always ask my conversation buddy - "What about 2FA? Do you use YUBIKEY?"

To my big surprise, majority, maybe 95% or more usually reply "YUBIKEY !? What the hell is that?"

I got my very first YUBIKEY device long ago, back perhaps 7 or 8 years. Over the time I've upgraded several times to a new, more modern and powerful models.
Recently I got the latest, 5 seriesYUBIKEY 5C NFC:

myyubikey5.jpg

As there are a bunch of variations available, it was a bit tricky to make a choice, which of them would fit my style of use and my needs at the very best.
Finally, I choose the one with USB-C connector, and NFC wireless connectivity. This model best fits mobile phones and tablets, but with little USB-C/USB-A adaptor (photo above) it should cover 99% of the situations I ever may encounter.

The full line of "Series 5" contains a selection of 6 different models:

yubikeysall.jpg
Photo Source

There are tons of information, comparisons, utilities and descriptions on the manufacturers home page

For everyone who deals with cryptocurrencies and online finance, this 2FA hardware gadget is an absolute must. Very much recommended.
Just like my mentioned (earlier today) TAILS, it can greatly reduce the attack vector surface to your private keys, be it Hive, LEO, CUB, Bitcoin, ETH, or anything else.

@onealfa


Posted via proofofbrain.io

Sort:  

keeping our keys safe is the most important thing and I use google 2fa for the second layer of security. I never used Yubikey but will check out more. I even near heard about it before. thanks for sharing about it ..

Posted Using LeoFinance Beta

Yeah it is a good gadget that is effective ...


Posted via proofofbrain.io

Never heard of this one before. Thanks for the reminder.

You can not be less carefull with security.
One small mistake and all the valuables (Fiat of Crypto money, important information/documents) can be gone in seconds without any trace.
Online hacking and scams are on rise these days and they always come with some new fancy way of tricking you.
I have been using 2FA from quite a some time now but i have been using soft tokens. I must check this one to see if i really need har done.
Thanks for sharing.


Posted via proofofbrain.io

Great tip, @onealfa.

I am using them since 2006 I think. I had so many that I even offered some as gifts to my friends. The Kingston ones were my favorites. Then I bought external hardware when I went to work in Paris, an antishock one. I have my info on external memory sticks now, in 2 cloud services (I'll get most of it out from there) and on my external hardware.

Thank you for your guidance and push to safely back up our data.


Posted via proofofbrain.io

I have like three of these sitting at home that I have never taken out of the package. I got them as gifts and I just haven't had the time to dig into them. I really wish they worked in conjunction with the Google mobile authenticator. I use that for a lot of things and being able to just connect it to that would be awesome.

Posted Using LeoFinance Beta

Google 2FA is good, I use it a lot too. In fact, I have moved all my 2FA keys grom Google's to AEGIS, as it gives a better flexibility, and ways to make a backups (your lost smartphone with Google authenticator and no backups can be a BIG disaster)
Plus, I am not so confidant if Googles tool is always possible to use.
Recently I am migrating from LASTPASS to a fully offline password manager KEYPASS, and not sure if KEYPASS is compatible with Googles 2FA. With proper plugin, KEYPASS works just fine with YUBIKEY, and no internet is required at all. Could be nice in a places where no WI-FI nor LTE/4G/5G is even possible.


Posted via proofofbrain.io

That is cool. Like I said, I really need to dig into this a bit more. I just got rid of Lastpass as well and I moved to BitWarden. I liked that it was open source and I signed up for a family account so my wife can use it as well. That is nice that you can use it without an Internet connection.

Posted Using LeoFinance Beta

Checking out their home page now. I have been meaning to up my security even though my stake is small. As it grows I want to make sure I'm organized, thank you for the recommendation!

Posted Using LeoFinance Beta

Never think you have spent to much time or/and money for your own security. It always below the bear minimum


Posted via proofofbrain.io

I suppose that you are correct. Building a solid base for security is probably important as you move forward. Starting with the basics is usually key


Posted via proofofbrain.io

It's supposed to replace 2FA from google on Binance for example or any other sites requiring it?

Why would it be safer than the regular 2FA?

Posted Using LeoFinance Beta

We need to secure our cryptos and ensure we are safe,thanks for sharing this amazing info about this wonderful security tool which will help us to secure our crypto effectively....@onealfa


Posted via proofofbrain.io

Thanks for raising awareness about this option. I've been using one for about 8 years, I think.


Posted via proofofbrain.io

Sadly, I guess I am pretty close to the 95%... whereas I have heard of Yubikey in passing and seen the name in posts/articles, I have never really looked at what it does, features and such.

Mostly, I've been using Google Authenticator, and it's been "OK" for the very limited needs I have had, so far. However, I expect "very limited" is going to grow, with time.

Anyway, thanks for the recommendation!

=^..^=

Posted Using LeoFinance Beta

I wasn't aware of YUBIKEY as well but was feeling the need of something like it for quite some time now.

Posted Using LeoFinance Beta

Facebook bought tails, I wouldn't use that software.

@phusionphil there must be a reason why you wouldn't want to use the software,can you tell me the reason??


Posted via proofofbrain.io

Tails took money from Facebook to make a backdoor in there software.

https://www.vice.com/en/article/v7gd9b/facebook-helped-fbi-hack-child-predator-buster-hernandez

Oh really?wow I am surprised to read that...now.i understand why you said you wouldn't use that software...@phusionphil


Posted via proofofbrain.io

I probably would say immediately "I wouldn't use that software.." as soon as I find something equivalent or better. So far - I have not.

Plus, the main TAILS advantages is not TOR or hiding my IP.
I'm not so concerned about my IP. In case I need this, I can easy go to KODACHI.

There are other things which I value more in TAILS

Posted Using LeoFinance Beta

A factor that convinced Facebook’s security team that this was appropriate, sources said, was that there was an upcoming release of Tails where the vulnerable code had been removed. Effectively, this put an expiration date on the exploit, according to two sources with knowledge of the tool.

As far as the Facebook team knew, Tails developers were not aware of the flaw, despite removing the affected code. One of the former Facebook employees who worked on this project said the plan was to eventually report the zero-day flaw to Tails, but they realized there was no need to because the code was naturally patched out.

From that article.

Still very sketchy and would need to look further into the legitimacy.


Posted via proofofbrain.io

I've "upgraded" my Yubikey to a 5 NFC a few months ago. Excellent tool, very robust. Never had any issues with it whatsoever.


Posted via proofofbrain.io

!PIZZA
!BEER
for you

Connect

Trade


@onealfa! I sent you a slice of $PIZZA on behalf of @eii.

Learn more about $PIZZA Token at hive.pizza

Sorry, out of BEER, please retry later...

This is a very clever little gadget, and something that I have never thought about seriously.

  • Many thanks for your technical insight, I will get myself one of these...

Posted via proofofbrain.io

Thank you for the tip.. How much can I get the cheapest one for

This is the first time i am hearing about it. Hope it does not cost an arm and a leg? I have had to give up a lot of those lately


Posted via proofofbrain.io

I have heard of and researched these devices before, but put it on the back burner. It’s definitely time to move it to the front.
Thanks for the reminder.

Posted Using LeoFinance Beta

Very very often the Email account is the very weakest link. So many people does not take it serious enough


Posted via proofofbrain.io

@onealfa.pob

Alot of phishing activities go on via emails so that is why need to be careful and also prevent phishing emails and phishing content...


Posted via proofofbrain.io