[a / b / c / d / e / f / g / gif / h / hr / k / m / o / p / s / t / u / v / vg / vm / vmg / vr / vrpg / vst / w / wg] [i / ic] [r9k / s4s / vip] [cm / hm / lgbt / y] [3 / aco / adv / an / bant / biz / cgl / ck / co / diy / fa / fit / gd / hc / his / int / jp / lit / mlp / mu / n / news / out / po / pol / pw / qst / sci / soc / sp / tg / toy / trv / tv / vp / vt / wsg / wsr / x / xs] [Settings] [Search] [Mobile] [Home]
Board
Settings Mobile Home
/g/ - Technology


Thread archived.
You cannot reply anymore.


[Advertise on 4chan]


File: file.png (845 KB, 1609x1918)
845 KB PNG
is this a meme
>>
>>109378307
Yubico? Yes. Security keys? No
>>
>>109378323
which one do i get
>>
>>109378337
Nitrokey, look at which specific model is best suited for you
>>
>>109378400
it's not even cheaper and it's some boutique shit i'd have to pay $50 to ship to europe
>>
>>109378412
who said anything about cheaper
>>
>>109378412
1. Built in Germany, so shipping should be free in the EU
2. The point isn't to get something cheaper but something secure. Yubikeys don't even have FOSS firmware
>>
>>109378444
>(((germany)))
not today officer
>>
File: Glow_Drip.jpg (29 KB, 500x500)
29 KB JPG
>>109378458
>NOOO YOU NEED TO USE THE CLOSED-SOURCE SECURITY KEY
Wow it took a while to finally push your agenda
>>
>>109378471
i look at their website they sell shit that glows through my monitor half of it snake oil
>>
>>109378513
>They sell glowie stuff like security keys which are definitely bad unless it's closed source!
>>
>>109378307
no idea about meme, but it's a trap
u2f, fido, webauth, all of it, the whole three-letter-glowie-endorsed shit
>>
>>109378531
>Having another independent factor is bad
>>
>>109378444
Yubikeys use FIDO2 which is opensourced. What they dont have open is their certs, which only used to authenticate real yubikeys are being used when setup so someone cant slip a dev look a like in it with clonable keys,
>>
>>109378590
>firmware
>>
>>109378597
of what? fucking usb key?
>>
>>109378605
You thought a yubikey has no firmware? Despite your extreme glow you don't seem to be the brightest
>>
>>109378444
>Built in Germany
I'm not interested in Turkish "tech"
>>
>>109378444
>shipping should be free in the EU
LOL
LMAO even
>>
>>109378400
>open sores
>it looks like a turd

Why is this always a rule
>>
>>109378307
I don't get the hype, isn't it better to store the keys in your brain? If someone breaks into your house, the key is probably plugged in or laying around somewhere. What is the use case?
>>
>>109378590
incomprehensible post

>>109381079
The point is that it's very hard to remember >= 128 bits for every account.
Also it would be very hard for you to create an ed25519 signature in your head.
>>
>>109378307
No. A physical second factor is like your fingerprint, your face or your anal print: it's easier to steal your email than to steal your yubikey.
>>
>>109381121
>A physical second factor is like your fingerprint, your face or your anal print
Not protected by the 5th Amendment?
>>
>>109378307
Security expert here. The answer depends on threat modeling. If you are a business facing phishing campaigns, it is not a meme. I've defeated professional cybercrime groups with proper implementation of these. End-users don't like them but if they keep feeding credentials to reverse proxies and don't do training, you don't have much choice. Pair your hardware key with conditional access rules if you can. You will also want to maintain an inventory and keep spares so you can deactivate and swap if any go missing or get stolen. Admins should have 3 in different places to prevent lockouts.

Now, if your adversary is a government then they won't help. Hardware keys and FIDO2 are not designed to stop a government from seizing things. The best defense for that is staying off their radar. I personally think most open source & privacy focused hardware + software is placebo; backdoors and tracking are inserted in many FOSS projects, often by contributors who work for various governments, especially the US. Full disk encryption (excluding Bitlocker) and running local services probably does the most to stall state actors. Obviously if you rely on CSPs, law enforcement will go to them for your data/metadata, and your 2FA method won't even matter.
>>
I use a pair and they're lovely. Passkeys, webauthn, U2F stuff for logging in and 2nd factor is amazing, and yubico authenticator is a killer app. Proper desktop TOTP, even scanning what you have on the screen for qr codes for instantly pulling in the shared secret. I got a pair of the USB-A variety for durability, actually a second one because I updated firmware.
Some people don't like this design mentality where firmware cannot be upgraded and prefer nitrokeys for that reason.
Heck, since it's an NFC tag I can even use it for entry at my hackerspace, and the one I carry around just lives on my keychain.
If you value peace of mind and actual security, this is worth it.
Also, yubikeys have two storage slots and you can do cool stuff with them, shove PGP keys if you want, or a part of your disk encryption key.
>>
>>109382509
>and you can do cool stuff with them
bring up at least 25 examples
>>
They're a meme.
>>
>>109381678
bro i just want one for my password manager so if i leak the password for it somehow i dont get fucked
>>
>>109382509
>2nd factor is amazing,
Bait use to be believable.
>>
File: 61gzHyofJEL._AC_.jpg (81 KB, 1001x1001)
81 KB JPG
>>109378307
Hey lemme see that for a sec
This? Don't worry about it. It's a tamagochi.
>>
>>109382559
not in my threat model
>>
>>109381678
You don't need a hardware token for this. Web adopting non-meme standards that have existed forever, mutual TLS or even OpenSSH's keyauth, would prevent phishing as well. Passkeys and all this shit is overcomplicated garbage to create more worthless software as a service and meme hardware companies.
>>
>>109378307
it really is. unless you have some insane threat model, TOTP in a password manager is 90% as safe and much more convenient.
t. actually have a yubikey (from my company)
>>
>>109382598
i shouldve specified: i want it for my password manager and nothing else
>>
>>109382559
and what are you going to do with that toy to a hardware token with a security element inside?
>>
>>109382618
I'm just gonna let Marauder take a peek, don't worry Ranjesh your key is still safe.
>>
>>109382751
>I'm just gonna let Marauder take a peek
so nothing. have fun, self-hating pajeet.
>>
File: back to pol.jpg (71 KB, 600x769)
71 KB JPG
>>109378458
>unironically uses his snowflake insecurities to shill proprietary software
>>
>>109381120
> incomprehensible post
when you set up yubikeys you can check they are real yubikeys, made by them and not some J33t H@xx0r verison.

This is important because if you wanted to subvert these, youd make fake ones with clonable or static reusuable keys on them. Then you could do normal MitM tactics on those users and simply press your cloned yubikey in your badnginx server or whatever.
>>
>>109382871
>what is 5 eyes
>>
Why not use a usb key instead? Don't know much about the domain tbdesu.
>>
>>109378307
I want to log into my work issued PC without touching my smartphone. I dont give a shit if the yubikey is pozzed and gets my companys PC pwned, its for my convenience not their security
>>
>>109378567
I already have two factor why do they want me to get a hardware key and lock it to that hardware device when I have a code that I can lock away and move to a new device if it gets lost or destroyed?
>>
File: file.png (903 KB, 1200x1200)
903 KB PNG
can i make something with this motherfucker that doesnt need a cable?
>>
>>109382559
Does this retard really think he's gonna hack into USB with wifi?
>>
>>109383069
My answer as a guy who tried to do exactly that:

> In theory
The whole idea is you tell apps/websites "hey I own this thing with id #ID so if you see anyone with this thing, that's me"
But you can't just give #ID to websites like that, because if they get pwn your id gets pwn. So instead you say "I can solve challenges with my ID", the website gives you one, you solve it, you're authenticated (I'm explaining public key encryption with hand gestures here)
Now the place where the challenge solving happens can't be the app/website, because you can't trust those, therefore... it has to happen on your device. And that's what a Yubikey/FIDOkey is: an overpriced USB key with a tiny processor.

> in practice
There's no fucking reason. Physical security is a godsend and would improve the lives of billions, starting with the people who have to manage the computers of drooling corporate morons. It is absolutely doable to just have rotating IDs on a basic USB key.
Buuuuut you don't make the rules ^^ Google and Yubikey sell the majority of these shits and guess what, they write the specs ^^ And the specs said you need the chip thingy ^^ bad luck hombre ^^ here's some free code we wrote with the specs we wrote that works on shit we sell ^^ have a good day sir ^^
>>
>>109378412
token2.eu
yes im a shill
no im not paid
i just think they're neat
>>
>>109383269
with an ugly nfc hat or a custom board, sure
>>
>>109383529
some chink definitely makes usb stick looking rpi 2040
>>
>>109383471
>recommended by microsoft
into the trash it goes
>>
>>109378337
A Yubico because they just werk.
>>
>>109384034
>>109383471
https://www.token2.eu/shop/product/token2-pico-rp2350-based-fido2-security-key
7 euro +tip +delivery

>>109384069
windows admins need their daily reassurance or they won't buy your product
>>
File: file.png (585 KB, 909x746)
585 KB PNG
>>109384223
chinks have it for cheaper
>>
>>109384265
>no link
>>
>>109383466
I LOVE MONOPOLIES!!!!111
>>
>>109384343
>>109383466
the spec is open though
understandable too
you have password managers capable of web authentication through software as well
you can run a device emulator and use that possibly
you can program an esp32-s3 or an rp2350 as one with just as strong secure elements (minus the tamperproof hardware certification)
you can implement in on your site with no restrictions
you can attest security keys just as well as tech giants through openly accessible fido metadata
the only way i can think of that corpos could do to you with weaponizing the specs is not allow you to use them as your only factor on their own services (passwordless, in other words)
>>
>>109383192
>why do they want me to get a hardware key
Unphishable
>lock it to that hardware device
Security key != passkey
>>
>>109384289
fukken aliexpress m8
>>
>>109384438
>the spec is open though
like they need to fucking hide at this point
>password managers
did you read the post?
>device emulator
did you read the post?
>you can implement in on your site with no restrictions
Yeah I can also implement dick-scanning access on dumbfuck.org, surely that's gonna move the needle
>>
>>109385078
phishable credentials need not apply
>>
File: 1667090148258260.jpg (151 KB, 1024x1024)
151 KB JPG
>>109378307
fido2 is great for securing access to password managers, but I lol whenever I see people using yubikeys as their primary authentication device for everything.

>lose yubikey or it breaks (unlikely but not impossible)
>brick themselves out of every account they had stored
>>
>>109385132
>fido2 is great for securing access to password managers
that's my usecase
>>
>>109385083
kek
"sir we're going to have to renew your creds. please don't mind the scissors"
>>
>>109385140
it seems like the most obvious usecase for personal use. For business? sure, yubikeys all the way. but it's just not feasible for personal use.

also I lol at people sperging about storing OTP codes in the same password manager. Buddy, if your password manager is compromised, you got bigger fucking problems than OTP codes being stolen. For most services, the OTP is merely a suggestion that they let you bypass with an email password reset or whatever.
>>
>>109384438
this still needs a chip, anon asked about a usb key
>>
>>109385557
where are your chipless usb keys
>>
>>109382943
Something that concerns the US which YubiKey is based in but not Germany which Nitrokey is based in.
>>
>>109378307
jus werks
>>
Aside from OPs physical hardware requirement, you can set up OTP in a lot of modern password managers. It's not nearly as secure, but it's an option if you don't want to pay $50 for the physical device.
>>
>>109386114
>pay $50 for the physical device
do americans really?
>>
>>109378307
>is this a meme
in a non corpo context, yes since you need at least 2 of them or else you risk of locking yourself out of the things you wanted to protect the most. in a corpo context you can just ask some admit to reset your stuff and give you a new key in case you lose the old one. That doesn't work for personal use so you always need some backup methods to access your accounts and/or a second key
>t. uses them in a personal and corpo context
>>
>>109386147
also the amount of sites that support them is kinda slim, it got better with passkeys but with passkeys you have to problem that the yubikey can only hold a certain amount of them (at least the newer version can hold up to 100 passkeys and not the previous 25)
>>
i have 2, they are fine
>>109382559
i wish it was that trivial, lmao
>>109383269
https://github.com/polhenarejos/pico-fido
>>
>>109384265
>>109386215
forgot to quote this one
>>
File: file.png (615 KB, 459x669)
615 KB PNG
>>109378307
No, it's a yugi key.
>>
>>109386223
both posts are mine so yknow
i'm either getting those or >>109384223
>>
>>109385571
> 8bit
> 30MHz
> 12K RAM
> not reprogrammable
(You): Yeah let's do PKI on that
>>
>>109378307
Be sure to glue an appletag to this so it can be found once you misplace it.
>>
>>109383370
You could hack into a system that uses a yubikey and install man-in-the-browser malware to fool the yubikey into signing for a remote browser controlled by a evilnginx server then MitM their login attempt
>>
File: glowniggers.jpg (110 KB, 1024x1024)
110 KB JPG
>>109386256
>appletag
>>
>>109386260
just punch the person in the face with gloves on at that point, retard
>>
>>109386146
This isn't an American thing. I'm not sure what you're getting at.
www.yubico.com/de/store/
www.yubico.com/gb/store/
>>
>>109381678
>Full disk encryption (excluding Bitlocker)
What do you recommend? TrueCrypt?
>>
>>109386256
Buy two. Register both on an account. Safe one. Keep the other plugged into the intended device. I think they have wireless connect options now too. They really are meant to be plugged into a device and left there till you no longer want users to use that system or services on it. Theyre really a method of proving physical access to a device like biometrics, but without the need for specific individuals. Basically corp networks.
>>
>>109386260
And using a yubikey causes all this to occur because...?
>>
>>109386279
you are insane...
NO ONE HERE IS CAPABLE OF PUNCHING ANYONE IN THE FACE HARD ENOUGH TO HAVE ANY EFFECT OUTSIDE OF GETTING THEIR OWN ASSES BEAT!
>>
>>109386175
1. you use the same api for both resident credentials (passkeys) and old style (not deprecated!) u2f credentials
2. the relying party (the server) controls the option deciding which one to use
3. most of them give you no choice (bad!) and will still use the old style u2f credentials you have infinite amounts of (its fine)
the difference between them is with u2f credentials the private key is first encrypted with the device master key and sent alongside the public key to be stored on the server

with discoverable credentials you have a limited amount of them, but the private key is stored on the device and the user has the ability to inspect and delete them

>>109386254
>strawman
still a chip retard, do you even read what you respond to?
the spec's not some monopoly and it's in no way overpriced to get a fido2 key now.
not to mention that the idea of using a usb key dies the moment someone motivated steals it.

>>109386299
nobody forces you to buy the specially branded yubikey(tm) $50 device with how many there are on the market
>>
>>109386260
>>109386345
it's bed time, s(kiddie)
>>
>>109386420
>someone motivated steals it
if someone is *that* much motivated and has all the information to do so, they'd rather just kill, capture or torture you
>>
>>109386420
>not deprecated!
i know but there's like 5 sites who support them and i essentially just use u2f for google and cloudflare (personally, at work it's a bit different)
>but the private key is stored on the device and the user has the ability to inspect and delete them
but it's still annoying that they hw key has to hold some site specific details and with that is limited on the amout of passkeys they can effectively store
>>
I have a couple. I think they’re great.
>>
>>109386492
sure but with a secure element behind my keys i can die knowing they get jack shit
and if they really want me to give them the pin i'll give it to them. the wrong one. three times. then puk. another three times.
with some usb key they can try forever and, provided it's encrypted in the first place, dump it in the cloud to crack. much less liability.
but let's be real neither you nor me will ever be in that situation
>>
>>109386544
>but let's be real neither you nor me will ever be in that situation
yeah that is the point
hardware keys are in that sense, usually a plus
>>
noob question but some computers have fingerprint readers, isn't that simply better?
>>
>>109386613
I can't take the fingerprint reader on my computer and use it on my phone or tablet.
>>
>>109386613
that's how windows hello will authenticate you to your TPM passkey store if you configure it so, yes.
dedicated devices with a fingerprint reader also exist, but at that point you'd need to think about your attack vectors
there's also the question of simply forcing you to authenticate with your finger
with a fido2 compliant biometric key you'd still need to input the pin on top of the fingerprint

>>109386642
technically, if we were magically transported into passkeyland, you'd simply use your phone to log into any account on any device and so, the fingerprint reader would become portable
i think that was the idea behind adopting passkeys by google and co. """cloud""" passkey storage with companies locked into using their infrastructure to prompt you to authenticate on your phone
>>
>>109386613
what makes it special isn't that you have to tap on it but that there's a chip on it that holds private data that you can't exfiltrate, nowadays other devices that too but as the other anon said they're portable in comparison to the chip on your phone/laptop/whatever
>>
File: gewgle.jpg (130 KB, 974x847)
130 KB JPG
no
>>
>>109386708
north korean hackers salivating on the prospect of exfiltrating some juicy secrets and money by taking over your email and applying to jobs as you
>>
>>109386260
I mean, if you have that level of access to the machine, you can just steal the login tokens anyways and find other ways to escalate to admin or whatever.
>>
>>109386702
my phone is pretty much always with me...
and I can use passkeys on it to anything with bluetooth, apple makes it relatively painless
Ok ok everything's pozzed but should i really buy and carry another widget...
>>
>>109378412
it's already too cheap for how useful it is
>>
here's another interesting (but time consuming) way to use a security key that supports PIV.
you can use something called mutual tls to allow access to users that present a valid certificate signed by a self-created certificate authority.
you'd need to install OpenSC and add it as a PKCS#11 provider, generate a certificate signing request
sign it with your own certificate authority using openssl,
point nginx/whatever to use your own certificate authority certificate for client authentication and load up the signed certificate on your piv-supporting security key.
now any time you connect to your site you'll have to have your key plugged in and select a certificate to authenticate with
>>
File: file.png (110 KB, 1264x532)
110 KB PNG
>casually takes away choice from the user
classic google
>>
>>109386908
>Ok ok everything's pozzed but should i really buy and carry another widget...
It's fairly small. I have one on my keychain and it's basically a non-issue.
>>
>>109386908
you can actually buy a fully featured security key in the form of a card
the negative is that you can't plug it via usb. only smart card or nfc is possible
>>
>>109382606
why? so you can get locked out of all your passwords if your hardware token(s) fail or you lose them or they get stolen?
>>
>>109378307
Yubico products break from looking at them the wrong way lol
>>
>>109387187
oh boy have i got a feature for you
you configure two or more security keys with challenge response support with the same secret key
you enter your password, tick a box to use challenge response from your key, press unlock and touch your key
congrats!!! you did it!!! and you have backups!!!
you could also even back up the secret key in a safe way! even more backups!!!
>>
>>109387226
so why the token at all?
I unlock mine at login with pam using the password entered at LUKS password prompt time, also initial automatic sign in with the same password, in pam.
>>
>>109387252
second factor
>>
>>109383471
not open sores
>>
File: 1784773490507199.gif (1.41 MB, 320x240)
1.41 MB GIF
>>109378444
>1. Built in Germany
and you know the germans make good stuff
>>
>>109387326
Thankfully you don't need to trust the germans through the power of open source
>>
>>109386314
NTA but LUKS is what I use and recommend.
>>
File: cert_selection.png (29 KB, 725x471)
29 KB PNG
>>109387101
>>
>>109378307
They work and they work well. Not everything supports FIDO2, which is a shame, but I guess you have to take into account your threat model for each account you make.
>>
>>109381678
>>109382537
I use them for this. Just make sure you have more than one like I said, preferably in different places. 3 registered keys is best practice.
>>109382582
We agree on Passkeys... They are indeed garbage. I recommend keeping authentication methods separate from computing devices, hence password managers like Bitwarden for TOTP and Yubikeys for critical accounts (and vulnerable end-users). It's cheaper and easier to register several hardware authenticators than buying multiple phones/tablets and safer than using one device as a passkey in a personal context. You can also protect them with a PIN. Biometrics are not worth serious consideration. Facial geometry and fingerprints have known weaknesses and can't easily be changed if they're exposed. FIDO2 is not overcomplicated and there is little 3rd party support for the things you mentioned (granted FIDO2 doesn't have great support either)
>>109387845
>>109386314
I recommend LUKS and Veracrypt. The original Truecrypt was amazing, but I wouldn't trust it at this point. There are almost certainly vulnerabilities that haven't been patched. Bitlocker is great in a corporate environment where you can link it to Entra/Azure, but MS likely has backdoors. The answer here goes back to threat modeling. If your threat model seriously includes the government, you shouldn't use electronics or they should be highly disposable. Stuxnet and the recent Scattered Spider arrest are capability indicators. They have zero days and relatively unknown forensic artifacts to use against high value targets
>>
>>109378307
at work it was either this or one of those shitty phone apps that gives you a code. Yubikey has never let me down.
>>
>>109378307
Got one for free at a loonux expo.
Use it to unlock my computer at boot, since I'm too lazy to always be typing the passphrase.
>>
>>109389453
Can you still use the passphrase if you don't have the yubikey?
>>
>>109389911
yes
>>
>>109378307
>lose it
>now you are fucked
>>
>>109390557
There's a reason why everyone and their mom recommends you to have more than one.
>>
>>109378307
I use yubikeys, they are excellent. Every important account I have is protected by a yubikey, and my yubikeys are protected by my firearms, one of which is on me at all times outside the home. Really good security setup.
>>
I bought a 2 pack of these years ago and I still haven't bothered to take them out of its packaging because I'm too lazy/scared that I'll fuck something up or lose them. I'll stick to using Aegis on my phone like a clueless retard
>>
what is the actual usecase? being protected against phishing? just dont be retarded and you can save $50.
>>
>>109384265
>chink backdoor
>>
>>109391035
Phishing, hacking, you name it. If you want access to my accounts, you not only need my username and password, but also a physical device that is in my home.

I also find touching the YubiKey to be a much lesser hassle than fucking around with one-time codes from an app.
>>
>>109388624
>>109391035
They are valuable in any scenario where your second factor can be stolen or abused. SMS can be diverted by social engineering customer support team at your phone company or intercepted during or after transit. TOTP secrets can be stolen from your password manager's customer vault data (think LastPass in 2022). Fingerprints can be lifted from things you've touched. Push notifications are vulnerable to fatigue and device compromise. Email has the same problems as SMS and really depends on the security of the provider and your account.

Yubikeys are vulnerable to physical theft but can easily and cost effectively be unregistered and replaced. Obviously there are other downsides and risks, but they are superior to most methods
>>
File: skeptical.gif (484 KB, 300x225)
484 KB GIF
>>109378307
Yes, most people use their phone for that exact purpose.
If you have an Iphone, you can ltrl clone your phone and have a 2fa backup.

>>109378400
>look at random devices on website
>PERSONAL NAS
>its a 2gb RAM Pi4 with 240 GB SSD
>thats 360 bucks pls
>>
I got two of these but was only able to add it to two of my online accounts and those accounts have not yet requested hardware verification so idk how worth it it was.
>>
>>109390677
The keys aren't allowed to be duplicated, and not every site allows you to register multiple keys.
>>
>>109391608
Has to be a really shitty site to only allow one.
>>
It's a cool idea but if you actually want to use it, it's basically a standards nightmare and it sucks ass.
>>
Personally I think you're better off using an open-format OTP generator. You can save the secret for a generator in cold storage somewhere as a backup and do things like repudiation and stuff without being tied to hardware devices.
>>
>>109391608
i have it set up on the sites that matter and not only do they let you register >1 key, but also give you recovery codes
>>
>>109383269
i will never understand why they'd refresh but not swap it to usbc
just toss it and get anything arduino
>>
>>109391608
>The keys aren't allowed to be duplicated
Maybe not for passkeys, but you definitely can for OTP.
>>
>>109392894
Same goes for security keys which are not the same
>>
>>109378605
Do you know how a security key even works you fucking retard?
>>
File: .jpg (33 KB, 500x500)
33 KB JPG
>>109393376
no
>>
i have one it's shit
>>
No. It's a lifechanger if the sites you use actually support it and it works properly. There are definitely issues with it though especially for marginalized communities. The push for 2FA can create a real spiral for people if they lose their authenticators/devices and happen to be poor. To an extent, it is a form of artificial/monetary gatekeeping. I'm all for increased security but there should always be a human being I (or anyone) is able to talk to with regards to such things
>>
>>109396592
>lifechanger
how has it changed your life?
>marginalized communities
hardware tokens are the last thing poorfags would worry about
>>
>>109396627
It just makes life legitimately easier. You don't have to worry about password managers or any of that nonsense. You put the key in. Push the button. You login. It's secure. You don't have to stress it too much.

>hardware tokens are the last thing poorfags would worry about
Be serious
>>
>>109396645
>You put the key in. Push the button. You login.
what about the second factor?
>>
>>109396645
That sounds really insecure
>>
>>109396724
Yubico is certified.
>>109396675
It can be one. It can also be the only one.
>>
>>109396740
oh, so the "It's secure" part was meant to be ironic. got it.
>>
Cryptocurrency is a meme yes



[Advertise on 4chan]

Delete Post: [File Only] Style:
[Disable Mobile View / Use Desktop Site]

[Enable Mobile View / Use Mobile Site]

All trademarks and copyrights on this page are owned by their respective parties. Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.