{"id":4915,"date":"2019-01-22T05:57:16","date_gmt":"2019-01-22T11:57:16","guid":{"rendered":"http:\/\/blog.zoha-islands.com\/?p=4915"},"modified":"2019-01-22T05:57:16","modified_gmt":"2019-01-22T11:57:16","slug":"are-you-ready-for-hardware-security-keys","status":"publish","type":"post","link":"https:\/\/zoha-islands.com\/blog\/are-you-ready-for-hardware-security-keys\/","title":{"rendered":"Are You Ready for Hardware Security Keys?"},"content":{"rendered":"<table border=\"0\" width=\"100%\">\n<tbody>\n<tr>\n<td valign=\"top\">\n<div class=\"intro\">\n<p>Are you tired of unlocking your phone or computer a hundred times a day? Would you like to login to all your favorite websites with a single tap, and never remember another password? That&#8217;s the promise of hardware security keys. Let&#8217;s take a look at the current offerings, and you can decide if one is right for you&#8230;<\/p>\n<\/div>\n<\/td>\n<td><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<div id=\"adsense-new\"><\/div>\n<div id=\"a005432more\">\n<div id=\"more\">\n<div class=\"KonaBody\">\n<h2>You Might Want One of These On Your Keychain<\/h2>\n<p>Last summer, \u201chardware authentication\u201d was briefly buzz-worthy thanks to Google\u2019s announcement of the Titan Security Key. It was pretty impressive to read that 85,000 Google employees who used Titan went a whole year without a single compromised account. Google urged everyone to upgrade to hack-proof hardware authentication. Today, you can buy the Titan Security Key for $50 in the <a href=\"https:\/\/store.google.com\/us\/product\/titan_security_key_kit?hl=en-US\" target=\"_blank\" rel=\"noopener\">Google Store<\/a>.<\/p>\n<p><span id=\"ezoic-pub-ad-placeholder-116\" class=\"ezoic-adpicker-ad\"><\/span>Unfortunately, it doesn\u2019t look like many consumers are buying Titan, or any of its competitors. Whether the problem is cost, convenience (another thing on a keychain), or apathy to security concerns, hardware gadgets like Titan and the <a href=\"https:\/\/www.yubico.com\/\" target=\"_blank\" rel=\"noopener\">Yubico YubiKey<\/a> just have not caught on among private citizens. But that hasn\u2019t prevented the rise of many copycat products, some of dubious quality.<span id=\"ezoic-pub-ad-placeholder-111\" class=\"ezoic-adpicker-ad\"><\/span><span id=\"div-gpt-ad-askbobrankin_com-medrectangle-4-0\" class=\"ezoic-ad\"><\/span><\/p>\n<p>Yubico, the leader of this small, slow-moving pack, has at least seven YubiKey products for various applications. The classic <a href=\"https:\/\/amzn.to\/2AQhrfP\" target=\"_blank\" rel=\"noopener\">YubiKey 4<\/a> ($40 on Amazon) gets a 4-star rating average from 286 customers, making it the most popular model by far among Amazon shoppers. The YubiKey works with Gmail, Facebook, Dropbox, Twitter, Dashlane, LastPass and &#8220;hundreds of other services.&#8221; It&#8217;s also touted as waterproof, and crush resistant. Just plug YubiKey 4 into a computer&#8217;s USB port and tap the gold circle to activate. If you don&#8217;t want something that big on your keychain, the $50 <a href=\"https:\/\/amzn.to\/2SYdhth\" target=\"_blank\" rel=\"noopener\">YubiKey 5 Nano<\/a>, works the same and is about the size of a dime. <img decoding=\"async\" loading=\"lazy\" class=\"alignleft wp-image-4931\" src=\"http:\/\/blog.zoha-islands.com\/wp-content\/uploads\/2019\/01\/HW-Security-key-300x225.jpg\" alt=\"\" width=\"567\" height=\"425\" srcset=\"https:\/\/zoha-islands.com\/blog\/wp-content\/uploads\/2019\/01\/HW-Security-key-300x225.jpg 300w, https:\/\/zoha-islands.com\/blog\/wp-content\/uploads\/2019\/01\/HW-Security-key.jpg 600w\" sizes=\"(max-width: 567px) 100vw, 567px\" \/><\/p>\n<p>The <a href=\"https:\/\/everykey.com\" target=\"_blank\" rel=\"noopener\">EveryKey<\/a> wants to replace not only your passwords but also the heavy, noisy mass of metal keys you carry everywhere. Everykey generates secure passwords for your website accounts, and will unlock them with one touch. It also promises to unlock your phone, laptop, and at some time in the future, your house and car, as long as they have Bluetooth capability. When your Everykey is close to one of your devices, you can access it without a password. When you walk away, your device locks back down.<\/p>\n<p><span id=\"ezoic-pub-ad-placeholder-112\" class=\"ezoic-adpicker-ad\"><\/span><span id=\"div-gpt-ad-askbobrankin_com-box-4-0\" class=\"ezoic-ad\"><\/span>And yes, that\u2019s antivirus pioneer John McAfee on EveryKey\u2019s home page and in its video. McAfee claims he founded EveryKey in 2015, but fundraising for the venture seems to have started as much as <a href=\"https:\/\/medium.com\/@DEFCON_2015\/everykey-scam-is-a-good-reason-to-dump-mgt-shares-d3d4635f6bc5\" target=\"_blank\" rel=\"noopener\">three years earlier<\/a>. EveryKey\u2019s original $99.99 price has eroded to <a href=\"https:\/\/amzn.to\/2VZb8PR\" target=\"_blank\" rel=\"noopener\">$59.20 on Amazon<\/a>, where it has a 2.5 star rating average from only 22 customers. <span id=\"ezoic-pub-ad-placeholder-117\" class=\"ezoic-adpicker-ad\"><\/span><\/p>\n<hr \/>\n<p>The <a href=\"https:\/\/amzn.to\/2AMaYlN\" target=\"_blank\" rel=\"noopener\">Fetian ePass NFC FIDO U2F Security Key<\/a> ($16.99 on Amazon) sounds like a mouthful of acronym soup, but it\u2019s not hard to parse. \u201cNFC\u201d means it works with Near Field Communication, the protocol that enables tap-and-go payments via smart cards or phones. \u201cFIDO\u201d is the Fast ID Online set of security standards developed by nearly 300 members of the FIDO Alliance to ensure interoperability. \u201cU2F\u201d is the <a href=\"https:\/\/www.yubico.com\/solutions\/fido-u2f\/\" target=\"_blank\" rel=\"noopener\">Universal 2-Factor authentication standard<\/a> developed by Google and Yubico. Customers give the ePass 3.5 stars. Complaints among a total of 89 reviews include dead-on-arrival units, another that failed after five months, and no tamper-proof packaging.<\/p>\n<hr \/>\n<p>The <a href=\"https:\/\/amzn.to\/2sv0Sl1\" target=\"_blank\" rel=\"noopener\">Thetis Security Key<\/a> ($16.95 on Amazon, is also FIDO and U2F compliant, and gets an impressive 4.5 stars from 181 customers. Unlike pricier products that leave delicate gold-plated contacts exposed, the Thetis\u2019 rugged, foldable design guards against mishaps.<\/p>\n<p>A Thetis reviewer made an interesting observation: \u201cTechnically, very few sites supports U2F protocol, BUT Google and Facebook are INCLUDED. And, as you know, Google and Facebook provides authentication for millions of sites. So, using U2F for Google and Facebook and using them for authentication covers, literally, millions of sites.\u201d I guess he\u2019s OK with Google and Facebook tracking every site he visits.<\/p>\n<hr \/>\n<p><span id=\"ezoic-pub-ad-placeholder-113\" class=\"ezoic-adpicker-ad\"><\/span>The cheapest gadget definitely looks the part. The <a href=\"https:\/\/amzn.to\/2AQja4B\" target=\"_blank\" rel=\"noopener\">U2F Zero<\/a> is no more than a bare circuit board, probably hand-made to order by a geek named \u201cConor\u201d at his kitchen table. But it\u2019s U2F compatible, gets 4.0 stars from 60 reviewers, and it\u2019s only $9.86.<\/p>\n<p>Even though they seem handy, I think it unlikely that hardware authenticators will ever catch on as aftermarket purchases. Even the bare-bones U2F Zero is ten bucks that most people won\u2019t spend to replace free passwords. But these devices may find their way into OEM devices, becoming a standard \u201caccessory\u201d just like a phone charger.<\/p>\n<p>Are you interested in a hardware security key that can manage your logins, and unlock your gadgets? I personally have many passwords for many programs, websites, cellphone, computers and forget passwords on accounts in secondlife so much I purchased and use\u00a0 <a href=\"https:\/\/amzn.to\/2AQhrfP\" target=\"_blank\" rel=\"noopener\">YubiKey\u00a0 <\/a>for all. Of course keeping your passwords secure is always the key and changing them often helps in this. In weeks to come we will cover the how to on passwords and updates with these keys.<\/p>\n<p>Have a great week<\/p>\n<p>ZI STAFF<\/p>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Are you tired of unlocking your phone or computer a hundred times a day? Would you like to login to all your favorite websites with a single tap, and never remember another password? That&#8217;s the promise of hardware security keys. Let&#8217;s take a look at the current offerings, and you can decide if one is &hellip; <a href=\"https:\/\/zoha-islands.com\/blog\/are-you-ready-for-hardware-security-keys\/\" class=\"more-link\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":4930,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[2,3,4,5,6],"tags":[],"_links":{"self":[{"href":"https:\/\/zoha-islands.com\/blog\/wp-json\/wp\/v2\/posts\/4915"}],"collection":[{"href":"https:\/\/zoha-islands.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zoha-islands.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zoha-islands.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/zoha-islands.com\/blog\/wp-json\/wp\/v2\/comments?post=4915"}],"version-history":[{"count":0,"href":"https:\/\/zoha-islands.com\/blog\/wp-json\/wp\/v2\/posts\/4915\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/zoha-islands.com\/blog\/wp-json\/wp\/v2\/media\/4930"}],"wp:attachment":[{"href":"https:\/\/zoha-islands.com\/blog\/wp-json\/wp\/v2\/media?parent=4915"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zoha-islands.com\/blog\/wp-json\/wp\/v2\/categories?post=4915"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zoha-islands.com\/blog\/wp-json\/wp\/v2\/tags?post=4915"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}