Earlier quoted context omitted.
You must not be using the new macbooks...
What's preventing USB-C Yubikeys? So you need an adapter right now...
Google Determines that FIDO U2F Security Keys Improve Security
41–50 of 69 posts
Re: Google Determines that FIDO U2F Security Keys Improve Security
#42Ever since adopting a security key, I've had to set my user-agent to Firefox (to prevent the U2F auth attempt) and fall back to Google Authenticator for 2FA.
Re: Google Determines that FIDO U2F Security Keys Improve Security
#43Earlier quoted context omitted.
Phishing is a top threat to users and enterprises both. OTPs, whether from SMS or not, can be easily phished as well as passwords, while U2F cannot. So the answer seems fairly clear.
OTPs must be phished and then used very rapidly. The ROI for a successful phishing is much lower: a database of old OTPs is much less useful. (I'm sure you could use that to break the secret, but it's definitely not storing the secret.)
Re: Google Determines that FIDO U2F Security Keys Improve Security
#44Earlier quoted context omitted.
You also need to have the password database. Having the master password alone is not sufficient, and having the password database is not sufficient. And of course the master password never gets transmitted over the network, so it's harder to get. If your threat model is an attacker that's compromised your specific computer (as opposed to a network attacker) then yeah, having the OTP code in your password manager isn'…
No, it by absolutely no means whatsoever is 2FA, no matter how you slice it. Regardless of where your password database is, the attacker only needs to compromise 1 password on the website to access your account. It doesn't matter how they got that password, your physical devices are irrelevant. With 2FA, the attacker would also need access to the secondary device that has the secondary authentication, whether that be…
What are you talking about? The whole point of TOTP is if the attacker compromises your password, they still can't log in because they don't have the TOTP code.
Re: Google Determines that FIDO U2F Security Keys Improve Security
#45Yea seems right, U2F keys are very sound security-wise. The biggest challenge I've found is the obvious: ease of use. It can be kinda clunky to need to pull out a key and plug it in to a USB port in order to log in to Github, for example. That said, this is mitigated pretty well usually with the "thumbnail USB" style key (like Yubikey has) where you pretty much keep it plugged in all day and click it when you need to…
The yubikey neo support NFC. Comparison here: https://www.yubico.com/products/yubikey-hardware/ (Edited my comment to correct a mistake)
Re: Google Determines that FIDO U2F Security Keys Improve Security
#46Yea seems right, U2F keys are very sound security-wise. The biggest challenge I've found is the obvious: ease of use. It can be kinda clunky to need to pull out a key and plug it in to a USB port in order to log in to Github, for example. That said, this is mitigated pretty well usually with the "thumbnail USB" style key (like Yubikey has) where you pretty much keep it plugged in all day and click it when you need to…
The yubikey neo support NFC. Comparison here: https://www.yubico.com/products/yubikey-hardware/ (Edited my comment to correct a mistake)
Re: Google Determines that FIDO U2F Security Keys Improve Security
#47Also curious if I can use a U2F for anything PGP-related, signing or encrypting regular stuff.
All this to save $20/piece!
Re: Google Determines that FIDO U2F Security Keys Improve Security
#48The comparison is to "One Time Passwords (OTP)via SMS phone messages." Given the vulnerabilities in GSM, that's not a high bar. http://security.stackexchange.com/questions/11493/
The big problem with TOTP is that real time attacks can still get you when you get MITM.
Edit: I now understand you were talking about the article, not the technology itself
Re: Google Determines that FIDO U2F Security Keys Improve Security
#49So is Yubikey and implementation of this standard or a competitor?
In some ways they are in technical competition but the company is making money regardless because they just implement both.
Re: Google Determines that FIDO U2F Security Keys Improve Security
#50Earlier quoted context omitted.
The yubikey neo support NFC. Comparison here: https://www.yubico.com/products/yubikey-hardware/ (Edited my comment to correct a mistake)
The only one that supports it appears to be an outdated model that isn't undergoing the latest certifications and lacks other features (like ECC p384)
I have some hope that a product like that is coming, I just don't know when.