Yubico is hosting their
Cyber Week Sale on
Yubico YubiKeys NFCs Authenticator Bundle Keys on sale listed below. Shipping is $4 (3-7 business days).
Thanks to community member
nicework for sharing this deal
Note, no coupon code is needed, just add the bundle of choice to cart and pricing will reflect at checkout
Be sure to select the United States as your country of origin during the shipping/contact menu
Example Options:
- 2x YubiKey 5C NFC Bundle Keys $82.50
- 2x Security Key C NFC by Yubico Bundle Keys $43.50
Leave a Comment
Top Comments
https://www.dongleauth.
https://www.kaspersky.c
Keep in mind. You lose the 2fa dongle or phone without having a backup way to get into your accounts = you're totally screwed.
So most people buy 2+ dongles and store 1 offsite.
Or backup their phones and 2fa app completely.
66 Comments
Sign up for a Slickdeals account to remove this ad.
I don't think this is well advertised but 2FA is build into the Apple password manager. So now I use this which I think is more secure as it requires biometrics to get to. And you can call the stored 2FA any name for obscurity.
I don't think this is well advertised but 2FA is build into the Apple password manager. So now I use this which I think is more secure as it requires biometrics to get to. And you can call the stored 2FA any name for obscurity.
I don't think this is well advertised but 2FA is build into the Apple password manager. So now I use this which I think is more secure as it requires biometrics to get to. And you can call the stored 2FA any name for obscurity.
So assuming you are using iCloud for practically everything like most people are, across multiple devices, including passwords, then the value of protecting your Apple account skyrockets.
Ask anyone who has had their Apple account hacked if they could pay $100 to get it back if they could (the cost of two yubikeys) most will say yes.
Sign up for a Slickdeals account to remove this ad.
https://www.yubico.com/works-with...rt=popul
E.g. YubiKey 5 NFC
...
Not every account supports yubi.
E.g. Banks often don't care about the 2fa hardware devices and simply use a phone text message because a. They've got a 24/7/365 location lock on your ass that 3rd party data brokers can give them b. They know when your phone is at a wierd location based on zillions of days tracking you c. The biometric (fingerprint etc) security on your phone works d. It works well enough for them despite sim swapping etc cheaper than the zillion support calls they'd get with a hardware device.
Our community has rated this post as helpful. If you agree, why not thank babygdav
Hacked....
1 password https://www.bleepingcom
Lastpassword
https://www.bleepingcom
Titans, rsa, etc ....
One never knows if a hacked device actually has competent IT guys to fix their mess or not.
Definitely not lastpass that's seen multiple issues reported (they're just like experian).
Also, it is HIGHLY recommended to buy these in pairs and set them both up in case you physically lose your key.
https://www.engadget.co
Edit: Nevermind the website answered my question, the offer 5 bundle for 455.
https://cdn0.tnwcdn.com/wp-conten...hic@2x
Notice how text messages are 96% effective in preventing account take over.
Hardware 2fa keys only address that 4% gap should you be targeted. (Versus the other jucier targets who have billions of dollars, state secrets, etc)
...
https://support.apple.c
https://www.security-embedded.com...-in-safari
It's complicated.
With websites and browsers, the push is away from exchanging passwords to pushing across cryptographic keys info.
This means I don't tell you the password, but you give me a long number and I tell you a new secret word that only us two knows how to look up (e.g. Number is the nth word in the bible).
....
So for most websites, apple security chip only protects the list of passwords, but passwords are still sent online.
As websites move to passkeys, iPhones can replace yubis since both are 2fa devices that won't exchange passwords.
For those today that want 2fa, they can also run authenticator apps on iPhones free. The 2fa apps are generally locked behind iPhone security to turn on the phone and get in BUT if your phone gets hacked thru an online attack, then the hackers get access to your 2fa app as well (unlike a hardware key where they'll need to come to your house).
Tons of zero day hacks that can take over phones discovered yearly.
Eg. https://citizenlab.ca/2023/09/bla...-the-wild/
So yes, Russia can get into your phone if they wanted to.... But realistically, modern phone biometric security with a 2fa app / password manager is "sufficient" to significantly reduce the likelihood you'll be hacked by the kids and lower level hackers.
Meaning, you can secure everything to the point where the baddies must come get you to get in to your accounts, but I don't think they'd mind breaking into your home and taking your phone and finger if they truly wanted in.
....
Better tact is isolate and separate.
E.g. One email with one provider and one password for banking.
Another totally different one for general emails.
Never log into both simultaneously, always set web browser to remember nothing and always clear cookies and everything upon exit, and always close browsers immediately after use.
....
To get started using passkeys on the iPhone
https://www.pcmag.com/how-to/no-m...y-sign-ins
A limited number of websites support it.
https://passkeys.direct
As for how long iPhone security hardware can withstand attacks:
https://tech.hindustant
https://www.theverge.co
Like water falling on stone, hackers will find their way in someday.
Sign up for a Slickdeals account to remove this ad.
Leave a Comment