Live data from Hacker News

Google Determines that FIDO U2F Security Keys Improve Security

eweek.com

51–60 of 69 posts

Re: Google Determines that FIDO U2F Security Keys Improve Security

#51

Earlier quoted context omitted.

The yubikey neo support NFC. Comparison here: https://www.yubico.com/products/yubikey-hardware/ (Edited my comment to correct a mistake)

The only one that supports it appears to be an outdated model that isn't undergoing the latest certifications and lacks other features (like ECC p384)

My bad. There was at least another one that did NFC, but it must be a discontinued model and removed from the page since I last looked at it.

Re: Google Determines that FIDO U2F Security Keys Improve Security

#52

Earlier quoted context omitted.

OK...but Google and my bank still use OTP over SMS to two-factor authenticate me. So clearly there's room for discussion and evangelism here. NIST can say that pigs fly, but until I see it in the wild I'm going to take it with a grain of salt.

Just so you know, you can also use Google Authenticator if you really dislike SMS. Make sure to back up those emergency keys though, and read about encrypting your iTunes backups so it'll actually back up the GA settings.

Even better is to buy a Yubikey, for those services that already support U2F use that. For those that do not, use the Yubico Authenticator and your Yubikey over NFC. You care one key around and no secrets are ever on your phone.

Re: Google Determines that FIDO U2F Security Keys Improve Security

#53
post #47

How can I use U2F for Windows sign-on? Windows 10 "Hello" stuff is apparently in the pipeline, but I need U2F domain authentication for Windows 7+. Also curious if I can use a U2F for anything PGP-related, signing or encrypting regular stuff. All this to save $20/piece!

> Also curious if I can use a U2F for anything PGP-related, signing or encrypting regular stuff.

You can! This works mostly out of the box if you enable it using the manager application (looks like newer models may have it on by default) and install the required gpg smartcard stuff.

https://www.yubico.com/support/knowledge-base/categories/art...

Re: Google Determines that FIDO U2F Security Keys Improve Security

#54
post #47

How can I use U2F for Windows sign-on? Windows 10 "Hello" stuff is apparently in the pipeline, but I need U2F domain authentication for Windows 7+. Also curious if I can use a U2F for anything PGP-related, signing or encrypting regular stuff. All this to save $20/piece!

> Also curious if I can use a U2F for anything PGP-related, signing or encrypting regular stuff. You can! This works mostly out of the box if you enable it using the manager application (looks like newer models may have it on by default) and install the required gpg smartcard stuff. https://www.yubico.com/support/knowledge-base/categories/art...

No I mean the one key that isn't listed on that page... the $18 FIDO U2F Security Key.

Thanks for pointing this info out though!

Re: Google Determines that FIDO U2F Security Keys Improve Security

#55
The FIDO/Google blog post about it: https://fidoalliance.org/case-study-series-google-security-k...

And the actual study: http://fc16.ifca.ai/preproceedings/25_Lang.pdf

(Which helps answer some of the arguments in the discussion thus far. In particular, on page 11, they list the systems they compare against: SMS OTP, Google phone-based OTP, and three hardware tokens, including the FIDO U2F. They compare in Figure 6 explicitly with SMS OTP and app-based OTP.)

Re: Google Determines that FIDO U2F Security Keys Improve Security

#56
post #34

Earlier quoted context omitted.

Partial quoting an article to the go on to disagree with the core premise and good security will net you no sympathy from me. But the burden is on you to update it make it clear what you're referring to. If you think that this is truly unfair then I apologize for only reading your post and the linked article and not the entire historical context. But I think even without that, you went on to make a point counter the…

Partial quoting? I quoted the relevant bit. I may as well accuse you of partial quoting too since you "only" quoted one sentence and not the surrounding sentences. > But the burden is on you to update it make it clear what you're referring to. Not when I can't edit the comment anymore. When I edited my comment to say the title has been changed, the title had just been changed to say "SMS OTP" instead of "OTP", so it…

The primary problems with OTPs include input error and expiration windows. These are not fixed by making them push notifications. Further, there are many platforms where push is not an option or were SMS vs Push would not make a difference.

So no. Absolutely not. SMS is an additional problem, but OTPs in general suffer from logistic issues separate from their medium.

Re: Google Determines that FIDO U2F Security Keys Improve Security

#57
post #25
post #17

Earlier quoted context omitted.

You also need to have the password database. Having the master password alone is not sufficient, and having the password database is not sufficient. And of course the master password never gets transmitted over the network, so it's harder to get. If your threat model is an attacker that's compromised your specific computer (as opposed to a network attacker) then yeah, having the OTP code in your password manager isn'…

If all the factors are on the same box, it's just one factor.

The main concern for people using TOTP from a password vault is attacks against the websites they are visiting, not compromise of their password vault.

So no, the two factors are not on the same box being attacked, in the threat modes of interest.

For the threat of "my stuff was stolen" then both factors are in the same box, so even having a separate piece of hardware is no use (unless you can convince the thief to not take everything and please leave the authenticator dongle behind).

Re: Google Determines that FIDO U2F Security Keys Improve Security

#58

Earlier quoted context omitted.

OK...but Google and my bank still use OTP over SMS to two-factor authenticate me. So clearly there's room for discussion and evangelism here. NIST can say that pigs fly, but until I see it in the wild I'm going to take it with a grain of salt.

Just so you know, you can also use Google Authenticator if you really dislike SMS. Make sure to back up those emergency keys though, and read about encrypting your iTunes backups so it'll actually back up the GA settings.

If the bank doesn't support RFC 6238 OTP, Google Authenticator will not help.

Re: Google Determines that FIDO U2F Security Keys Improve Security

#59
post #39
post #32

Earlier quoted context omitted.

What's preventing USB-C Yubikeys? So you need an adapter right now...

Apparently, lack of market demand [0]. As for adapters: they significantly increase the profile of the yubikey nano, which I feel is a dealbreaker in that particular case, as the main selling point of the nano (to me, at least) is the always-plugged-in capability (see the image on the far right in [1]). [0] https://www.yubico.com/2016/07/yubikey-route-usb-c/ [1] https://www.yubico.com/products/yubikey-hardware/yubike…

Agreed! The best part about my Yubikey Nano is that I don't know its there and don't have to be careful about knocking it off. Invisible security is the best security. :)

Re: Google Determines that FIDO U2F Security Keys Improve Security

#60
One thing that struck me while reading this announcement is that if Apple had gotten on board with this idea the latest MacBook Pro may have had a better reception. Imagine hardware specifically built into your laptop to facilitate FIDO U2F security keys. Whether that's a device like those offered by YubiKey or an NFC reader, making U2F available and simple to use would be a great thing. Maybe it could even replace GPG/PGP for common uses.

Then again, maybe the recent Bluetooth 5 announcement will be enough to drive adoption. Or possibly the next iPhone / Pixel could act as a U2F device. Maybe then we could get "normal" people to use real security instead of asking them what street they grew up on or what their mother's maiden name is.

Post reply on HN