14 pointsby dblitt4 hours ago4 comments
  • jtrn29 minutes ago
    I'm a bit emotional after an extremely long and aggravating day at work, so this is probably situational based, but I HATE the whole god damn security field, and this is one of many examples of why.

    It's impossible to get simple explanations out of anybody in that field. And it's why security has always been a pain. It's like they're allergic to making plain, straightforward sense.

    Here’s what this actually means for people who expect stuff to matter in any practical terms.

    5.8 changes zero things about how you work. You cannot upgrade older keys to it, you have no reason to buy it, and the two features actually in there have never once been used by anyone outside a lab. The WebAuthn thing could, in theory, make the browser remember your key so you don't have to pin every time you use it, but that only happens when Apple, Google and others implement this proposed standard. Right now, no browser can call it. Not Chrome, not Safari, not anything. The spec is an open pull request. If it ever ships it's years out, and it wont be you that starts using it first, it would have to be some big auth entity.

    The ARKG thing: same, plus it needs a wallet ecosystem that doesn't exist yet.

    Yubico shipped firmware whose headline features nothing can currently use, is not relevant for existing hardware, and wrote three pages about AI to sell it. That's the actual story.

    bleh.

    • deepsun13 minutes ago
      But a manager came to my desk and asked "what can we do for the AI era"?
  • Varelion2 hours ago
    I believe in, and am a big proponent of physical 2FA being widely adopted -- though I own a half-dozen YubyKeys, I do wonder what their profit margins are. They feel a lot more expensive than they should be.
    • purpleflame1257an hour ago
      They used to be so cheap that WIRED offered them as signup freebies. I wonder what happened.
  • elevationan hour ago
    > New Era

    But no PQC?

  • FireBeyond2 hours ago
    They always neglect to mention that you can't (unless something changed recently) upgrade the firmware. It's carefully crouched in wording, but to read the site you'd say "Oh, so I just upgrade". No, you buy a new version of the device. And hopefully it's not like the last vulnerability when at least for a while they kept selling the vulnerable devices to deplete their stock unless you knew enough to ask for one specifically with the new firmware.