<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Security on WretchedGhost's Tech Blog and Rants</title><link>https://blog.lanlocked.xyz/tags/security/</link><description>Recent content in Security on WretchedGhost's Tech Blog and Rants</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sat, 21 Oct 2023 00:00:00 +0000</lastBuildDate><atom:link href="https://blog.lanlocked.xyz/tags/security/index.xml" rel="self" type="application/rss+xml"/><item><title>Two-Factor Auth and/or Passwordless Login on Arch Linux Using u2f Physical Keys</title><link>https://blog.lanlocked.xyz/post/u2f-auth-and-login-on-arch-linux/</link><pubDate>Sat, 21 Oct 2023 00:00:00 +0000</pubDate><guid>https://blog.lanlocked.xyz/post/u2f-auth-and-login-on-arch-linux/</guid><description>&lt;h3 id="credit-where-credit-is-due"&gt;Credit Where Credit Is Due&lt;/h3&gt;
&lt;p&gt;I used a lot of &lt;a href="https://old.jamesthebard.net/archlinux-and-u2f-login/"&gt;https://old.jamesthebard.net/archlinux-and-u2f-login/&lt;/a&gt; config but then tweaked it and added a litle more explination as his entry was from 2017~.&lt;/p&gt;
&lt;h2 id="lets-start-the-rant"&gt;Let&amp;rsquo;s Start the Rant&lt;/h2&gt;
&lt;p&gt;I have always wanted a way to get away from always having to type in password to login or use sudo. There are security concerns by allowing this type of login, one is the fact that anyone who possesses my key could then login and run as sudo, also is the factor that with some tweaking you can make it only allow for key entry via u2f &lt;code&gt;:lock:&lt;/code&gt;. A third way, which is the most secure way, is to have it where you must type in the password and possess the u2f hardware key to login.&lt;/p&gt;</description></item></channel></rss>