Convenience is the enemy of sovereignty.
If you rely on SMS or cloud-synced apps like Google Authenticator, you are not securing your account. You are just handing your keys to a landlord.
I ran a poll and 38% of you are still trusting Big Tech with your 2FA. I'm done with that. I trust physics, not luck.
In this video, I break down the four tiers of authentication, explain why I deleted Google Authenticator, and start my review of the top hardware keys on the market.
WebsiteMastodonLinkStackHARDWARE FEATURED (Tier 1)
Nitrokey 3A NFCToken2 PIN+ Dual Release 3.3YubiKey 5 NFC (affiliate link)SOFTWARE MENTIONED (Tier 2)
Aegis Authenticator (Android/GrapheneOS)Ente Auth (Desktop/iOS)Proton Pass (affiliate link)(Commissions help fund the hardware for Terminal Tilt!)
Ghacks.net - PSA: Raivo OTP for iOS was acquired by MobimeSafe Not Scammed - This Authenticator App Did What?Privacy Guides - Remove Raivo OTP (iOS MFA)Proton Pass GithubEnte Auth GithubYubico, Nitrokey, and Token2 provided the review units for this series. No money changed hands. No company saw this video before I hit upload. All opinions are mine.
๐จ THUMBNAIL: Created by me in GIMP.
No "AI" was used in the creation of this video or its assets.
Stay sovereign. Stay secure. Stay private.
#Privacy #Security #Linux #FOSS #Yubikey #Nitrokey #Token2 #SelfHosted