Finally a use for my security keys?
Speaking of OIDC, I searched in my drawer and found all three security keys I own again. A YubiKey 5C NFC with firmware 5.4.3 (apparently not so secure anymore and not upgradable) and two SoloKeys Solo 2 (one USB-A and one USB-C, both with NFC) I funded via Indiegogo many years ago. Those have upgradable firmware, so I managed to do that with the accompanying CLI.
After some research I also found a nice Linux app installable via Flatpak (keyroost) to manage the passkeys on the devices. I noticed that on the YubiKey I can just install 25, while on the Solo 2, I can install 100. It seems like the YubiKey isn’t really intended to be used with WebAuthn, so I guess I will prefer the Solo 2, as I don’t have a use for all the other features the YubiKey provides (yet), like saving certificates, etc.
I added a passkey on each key to log into Pocket ID. It also works fine using my phone, even with NFC. So far I have only used passkeys saved in Bitwarden, so using a hardware device to log into (private) services is a new experience, given I have only used such tools for complicated enterprise software so far. Now I can use the keys to log into my blog.
All that makes me think about saving some passkeys on the Solo 2 for some important accounts as some kind of “backup” for when there should be something wrong with my Vaultwarden setup. 🤔
Tags: Passkeys
