    274 points alexmolas | 11 comments
    1. 627467 ◴[] No.41083265[source]
    I love this, and have thought of doing the same with a dumb smartwatch but... is it good opsec to have top so visible/available? What about losing the watch or getting stolen?
    2. 0cf8612b2e1e ◴[] No.41083301[source]
    Unless the owner walks around proclaiming, “This is my second factor”, a casual observer is just going to think it is a broken watch.
    3. mcsniff ◴[] No.41083310[source]
    Eh, I keep TOTP codes on my Pebble and am fine with it, they are labeled in such a way that doesn't make it obvious what services they're for.

    There's basically no lock mechanism or security on a Pebble, but it's just a second factor.

    If you have my randomly generated password, have done your intel to know I might have the TOTP on my wrist, and can physically steal my watch, you've got me beat and I'm okay with that for the convenience it provides.

    4. hn92726819 ◴[] No.41084249[source]
    Also the firmware supports multiple faces. The default face can just be the time
    5. denysvitali ◴[] No.41084712[source]
    This is why you create a blog post and share it with the world /s
    6. collingreen ◴[] No.41084767[source]
    All security is a balance if the threat risk and the potential loss. I love that you have a mix that works for you while staying reasonable about it.

    We all have terrible, terrible tumbler locks on our doors because they are good enough to stop the extremely casual attempts but anywhere with unbarred windows is one rock from "unlocked" and we're generally fine with this for 99% of things.

    7. eurleif ◴[] No.41084781{3}[source]
    Security film is another option for windows.
    8. justincormack ◴[] No.41085645[source]
    Early totp devices were designed to look like pocket calculators when these things were less well known. But you are supposed to reset the key if you lose the device.
    9. marcus0x62 ◴[] No.41086002{3}[source]
    What's the threat model here? An attacker is going to read this person's blog post, track them down in real life, and steal their watch to get access to their github account? That seems...unlikely.
    10. patrickdavey ◴[] No.41086601[source]
    Less obvious than a ubikey though right?
    11. paulnpace ◴[] No.41087016[source]
    " he hid it, in the one place he knew he could hide something..."