Drew Church Profile picture
Security Strategist / #SURGe @Splunk, IP Officer @navy_reserve | Tweets/Likes are my own and do not represent my employers.
Oct 4, 2022 15 tweets 6 min read
We talk about #mfa all over #infosec - but even commodity items like the YubiKey aren't as easy as we need them to be. There's been TONS of progress on the non-IT/Dev user-facing side, but it's very messy elsewhere. Example: SSH Auth. 🧵 1/ 3 general approaches to using a security key for SSH: FIDO2, GPG, PIV. Each has pros and cons and levels of supportability. First, let's talk FIDO2. 2/