Live data from Hacker News

Show HN: A virtual Yubikey device for 2FA/WebAuthN

github.com

61–70 of 143 posts

Re: Show HN: A virtual Yubikey device for 2FA/WebAuthN

#61

Earlier quoted context omitted.

Not just phishing - you could lose your password via malware, or if services store passwords in clear text and get hacked.

I use different passwords for every service. Malware on a device where I'm logged into the service can use that authenticated session to access all the things I want protected. If the service is hacked, the hacker probably has direct access to everything the password was protecting.

> Malware on a device where I'm logged into the service can use that authenticated session to access all the things I want protected.

Any well-secured service should protect critical actions with 2fa. “oh, are you sure you want to transfer all your funds? Please re-authenticate first”

Re: Show HN: A virtual Yubikey device for 2FA/WebAuthN

#62
post #2

I can't figure out why I'd want a Yubikey. Every year or so I try to figure out if a 2fa device practically has sufficient support that using it would improve my security. The answer has always been no. No 2fa device has sufficient support that it could increase the security of my 1password account, which I use on Linux and Android. No 2fa device has sufficient support that it could be used to unlock the lockscreen o…

Your phrasing is odd. 2FA devices do not support websites. Websites support 2FA options. The problem isn't 2FA devices, but services not supporting 2FA. U2F/FIDO are standard at this point and many tech-related services support them; certainly, effectively all 2FA devices support them.

2FA is redundant for unlocking physical devices. Access to the device itself is already a second factor.

The point of 2FA is that someone MUST physically take something from you to gain access, which greatly limits attack vectors. If you use 2FA properly, the only thing you need to worry about for account security is whether you still have your 2FA key on you.

Re: Show HN: A virtual Yubikey device for 2FA/WebAuthN

#63
post #36

This sort of defeats the idea of 2FA, doesn't it? If it's implemented as a software service on the same device, it's (well theoretically at least) hackable at the same time as the device itself. The 2 factors from 2FA are both accessible to an attacker at the same time, so you effectively have just a single factor auth.

I'm a little confused here, but I thought 2fa was a combination of something I know (A password) and something I have (A authenticator). So a attacker getting access to your computer is same as them getting access to your authenticator?

Or do you mean that this leaves the secrets vulnerable to spyware and stuff? Cause in that case as the other comment says, one could use the TPM.

Re: Show HN: A virtual Yubikey device for 2FA/WebAuthN

#64
So, curious.

Anyone here do what I do, a simple encrypted Linux volume + "oathtool" powered script?

Yeah, I know, same device, blah blah. I'm still pretty comfortable with it and I just don't like having this stuff on my phone, which perpetually feels less safe.

Re: Show HN: A virtual Yubikey device for 2FA/WebAuthN

#65

Earlier quoted context omitted.

I use different passwords for every service. Malware on a device where I'm logged into the service can use that authenticated session to access all the things I want protected. If the service is hacked, the hacker probably has direct access to everything the password was protecting.

> Malware on a device where I'm logged into the service can use that authenticated session to access all the things I want protected. Any well-secured service should protect critical actions with 2fa. “oh, are you sure you want to transfer all your funds? Please re-authenticate first”

So if your device is compromised, the attacker could trick you into entering 2FA for some minor action while it actually is transferring all your funds.

If your PC or smartphone is compromised nothing will prevent you from losing control of your accounts.

Re: Show HN: A virtual Yubikey device for 2FA/WebAuthN

#66
post #36

This sort of defeats the idea of 2FA, doesn't it? If it's implemented as a software service on the same device, it's (well theoretically at least) hackable at the same time as the device itself. The 2 factors from 2FA are both accessible to an attacker at the same time, so you effectively have just a single factor auth.

It's still a second factor, just one that isn't as isolated as separate physical hardware. It's certainly more secure than a single password, while still giving the user absolute control over it.

I can see this being very useful for accounts which are effectively throwaway, but they still force you to 2FA. The same is true of TOTP generators.

Re: Show HN: A virtual Yubikey device for 2FA/WebAuthN

#67
post #36

This sort of defeats the idea of 2FA, doesn't it? If it's implemented as a software service on the same device, it's (well theoretically at least) hackable at the same time as the device itself. The 2 factors from 2FA are both accessible to an attacker at the same time, so you effectively have just a single factor auth.

Partially, but this still blocks many attacks that password alone wouldn't.

I always think of 2FA as insurance against password theft/leaks. If users don't practice good password practices and use the same password for multiple accounts, for example, when ${next web site to be hacked} leaks all plaintext passwords, you can't just turn around and use that password to access ${another site where I used the same password but have 2FA enabled}. Or I'm logging in to a site from someone else's computer and they have a keylogger. [Obviously this virtual 2FA device wouldn't let me log in in that scenario--but in general, this is another case where the 2FA doesn't have to be rock solid, it just needs to exist if you captured my keystrokes.]

A direct attack on my workstation to steal my virtual 2FA device and my passwords isn't protected by this virtual 2FA device, but that's low in my list of worries overall for people's account security.

Re: Show HN: A virtual Yubikey device for 2FA/WebAuthN

#68
post #65

Earlier quoted context omitted.

> Malware on a device where I'm logged into the service can use that authenticated session to access all the things I want protected. Any well-secured service should protect critical actions with 2fa. “oh, are you sure you want to transfer all your funds? Please re-authenticate first”

So if your device is compromised, the attacker could trick you into entering 2FA for some minor action while it actually is transferring all your funds. If your PC or smartphone is compromised nothing will prevent you from losing control of your accounts.

Which gives you more chance at detecting such an attack. Without 2fa, the funds are already gone.

Re: Show HN: A virtual Yubikey device for 2FA/WebAuthN

#69
post #6

Earlier quoted context omitted.

Can you define what do you mean by sufficient support?

Sure: Enough support so that my life becomes sufficiently easier or more secure to be worth the cost. I know that's a bit wishy-washy, but for example I think I could replace my memorized 1password password with something longer if I never had to enter it from memory, which would only be the case if I could use the Yubikey on all my devices.

Mobile access is one of the reasons I hope a near term next gen iPhone has USB-C support directly. The lightning / usbc yubikey dongle is just too unwieldy in my experience.

Re: Show HN: A virtual Yubikey device for 2FA/WebAuthN

#70
post #54
post #2

I can't figure out why I'd want a Yubikey. Every year or so I try to figure out if a 2fa device practically has sufficient support that using it would improve my security. The answer has always been no. No 2fa device has sufficient support that it could increase the security of my 1password account, which I use on Linux and Android. No 2fa device has sufficient support that it could be used to unlock the lockscreen o…

I use 1Password and 2 Yubikey. Both yubikeys are configured to enter the same impossible to memorize password on a press to unlock 1Password, hid mode is supported by every device with a USB ports. I also use them as an otp second factor when a site requires it. Finally, they are configured with a x509 certificate that I use as my ssh keys. I generate one key per devices that way the secret never leaves it and I requ…

Can you use the Yubikey as a keyboard on iOS?
Post reply on HN