So, the problem with USB tokens that we basically have two choices: - Unauditable black boxes built on *supposedly* more secure ICs that require NDAs to develop for - Open and auditable, but definitely pwnable off the shelf microcontrollers. Which poison do you prefer?
-
-
Also keep in mind that open does not mean secure, I've seen some absolutely abysmal firmware in "open" firmware projects along these lines too. I guess what I'm asking is whether it's worth doing #2 "right" with the caveat of being vulnerable to physical attacks.
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
Microsoft will happily log you in with the fido token only, and they’re pushing for this to be a standard across the web, so “only a 2nd factor” might hold true for now, but who knows for how long
-
What I don’t understand is why can’t all these vendors open source their firmware blobs and protocols for attestation of the device
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.